Qualys Security Advisory - userhelper / libuser

Discussion in 'News Aggregator' started by Packet Storm, 24 Jul 2015.

  1. Packet Storm

    Packet Storm Guest

    The libuser library implements a standardized interface for manipulating and administering user and group accounts, and is installed by default on Linux distributions derived from Red Hat's codebase. During an internal code audit at Qualys, they discovered multiple libuser-related vulnerabilities that allow local users to perform denial-of-service and privilege-escalation attacks. As a proof of concept, they developed an unusual local root exploit against one of libuser's applications. Both the advisory and exploit are included in this post.

    Continue reading...
     

Share This Page

Loading...