|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
IMWheel contains a flaw that may allow a malicious user to take control of the temporary file on the server. The issue is triggered when IMWheel creates an insecure temporary file (imwheel.pid) which manages the running IMWheel processes. It is possible that the flaw may allow a local attacker to escalate priveleges resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
IMWheel
 |
1.0.0pre11 |
|
|
|
|
Credit |
- Druid - druid
caughq.org -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|