>> Adobe Version Cue Local Privilege Escalation Vulnerabilities
Title : Adobe Version Cue Local Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2005-1504 CVE ID : CVE-2005-1842 - CVE-2005-1843 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-08-23
Technical Description
Two vulnerabilities were identified in Adobe Version Cue, which could be exploited by local attackers to obtain elevated privileges.
The first flaw is due to a design error in the setuid root application VCNative when handling the "-lib" command line option, which could be exploited by malicious users to load arbitrary libraries and execute arbitrary commands with root privilges.
The second vulnerability is due to a design error in the setuid root application VCNative when writing log files, which could be exploited by malicious users to supply data via the "-host" and "- port" options and execute arbitrary commands with root privilges.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.