CVE-2018-9310: High severity MagniComp Sysinfo vulnerability
An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Linux/UNIX systems running MagniComp SysInfo before 10-H82 are exposed when SysInfo is installed setuid root. The description states that this is the default configuration.
What does an attacker need to exploit it?
An attacker needs local access to the affected system and the ability to run SysInfo. No user interaction is required, and any local user can obtain a root shell.
How can I determine whether a system is affected?
Check whether MagniComp SysInfo is installed at a version before 10-H82 and whether its executable is configured setuid root. A vulnerable installation allows a local user who runs SysInfo to obtain a root shell.