Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

DSPAM Insecure Default Permissions Privilege Escalation Vulnerability

A vulnerability has been reported for DSPAM that may allow an attacker to execute arbitrary code with elevated privileges. The issue lies in the fact that DSPAM is installed world-executable and setgid by default.

The DSPAM application allows a user to specify various agents via the command-line. As a result, an unprivileged attacker may be capable of specifying a malicious executable to the application. When invoked, the executable will be run with the group privileges of DSPAM.

This privilege escalation could assist in further attacks launched against a target system.







 

Privacy Statement
Copyright 2009, SecurityFocus