exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ecl-channel.adv

ecl-channel.adv
Posted Nov 24, 2004
Authored by ECL Team

Local user input handling vulnerabilities exist in WCI's TC-IDE Embedded Linux prior to v1.54 which allow local users with access to the tools provided with the system to spawn a root console, gaining full control over the running Linux operating system. In corporate environments where this product is being used, such vulnerabilities could cause disastrous effects, all users are encouraged to update to the latest firmware ASAP.

tags | exploit, local, root, vulnerability
systems | linux
SHA-256 | 46d3aa11e83ba80562e7262440809b13893d555f6f58bc2ca80b55ac4797533e

ecl-channel.adv

Change Mirror Download
                [       ECL Security R&D       ]
Privilege escalation vulnerabilities in W-Channel embedded linux
+----------------------------------------------------------------+

Type: Local
Impact: Critical
Affected versions: all versions below v1.54


Product description:
-------------------+

Read https://www.tc-ide.com/eng/tcs-index.htm


Summary:
-------+

Local user input handling vulnerabilities exist in WCI's
TC-IDE Embedded Linux that allow local users with access to the
tools provided with the system to spawn a root console,
gaining full control over the running Linux operating system.
In corporate environments where this product is being used,
such vulnerabilities could cause disastrous effects, all users
are encouraged to update to the latest firmware ASAP.


Details:
-------+

We've found three methods of exploitation, explained below:

1) In the Net Tools dialog, type ";crxvt&" (without the quotes),
and click on Discover. A root shell within a virtual terminal
should appear.

2) In the PPPoE dailer GUI, type the same as above in the
username field, and click connect.

3) In Opera, click on Menu, then Preferences. In E-mail,
mark the "Use specific e-mail client" radio button,
and type "/bin/dillo" (without the quotes) in the textbox below.
Apply the settings, and close this menu. In the main window,
click on Mail, then Compose. The dillo browser window should
now be launched. Point it to the following address:
"https://localhost/cgi-bin/mycomputer.cgi". Go to the Control Panel,
then User Desktop. Enable "My Computer", then restart your desktop.
You should now have Adminitrator access to most of the settings.


Vendor correspondence:
---------------------+

Vendor informed: 15/10/04
Vendor reply: 17/10/04
Vendor fix release: 8/11/04


Fix:
---+

The security problems have been fixed and marked as v1.54 build,
Users should contact W-Channel for information on how to obtain the latest firmware.


Contact:
-------+

Yuri Gushin Alex Behar Valentin Slalov
yuri@eclipse.org.il alex@eclipse.org.il vns@eclipse.org.il
PGP: 0xFCE10121 PGP: 0x6896DEAD PGP: 0xA552D63B
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close