Release date:
Updated on:
Affected Systems:
Sourceforge WAN Emulator 2.3
Sourceforge WAN Emulator
Description:
--------------------------------------------------------------------------------
WAN Emulator is a wide area network simulator.
An illegal access vulnerability exists in WAN Emulator. This vulnerability can be triggered when setuid root is installed in the dosu binary file, which allows local attackers to obtain root privileges.
<* Source: Brendan Coles
Link: http://www.osvdb.org/85344
Http://www.metasploit.com/modules/exploit/linux/http/wanem_exec
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sourceforge
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://jocr.sourceforge.net/index.html