CVE-2010-0746: Path Traversal
A privilege escalation flaw was found in the way DeviceKit used to handle labels for pluggable storage devices. A local, unprivileged user could provide a specially-crafted string as a name, for the newly created / added system device, leading to escalation of his privileges.
Upstream bug report: -------------------- http://bugs.freedesktop.org/showbug.cgi?id=23235
Upstream patch: --------------- http://cgit.freedesktop.org/DeviceKit/DeviceKit-disks/commit/?id=62f883c7d38e75d0669c162529062a1e81d00da2
Other sources
Directory traversal vulnerability in DeviceKit-disks in DeviceKit, as used in Fedora 11 and 12 and possibly other operating systems, allows local users to gain privileges via .. (dot dot) sequences in the label for a pluggable storage device.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0746?
CVE-2010-0746 is considered a moderate severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2010-0746?
To fix CVE-2010-0746, update to the latest version of DeviceKit that addresses the directory traversal vulnerability.
Who is affected by CVE-2010-0746?
CVE-2010-0746 primarily affects users of Fedora versions 11 and 12, where DeviceKit is utilized.
What type of vulnerability is CVE-2010-0746?
CVE-2010-0746 is classified as a directory traversal vulnerability that allows unauthorized access through file path manipulation.
Can CVE-2010-0746 be exploited remotely?
CVE-2010-0746 cannot be exploited remotely but requires local access to the system to exploit the privilege escalation.