CVE-2014-7298

adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:centrify:directcontrol:3.0:*:*:*:*:*:*:*
cpe:2.3:a:centrify:directcontrol:4.2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:centrify:centrify_suite:2008:*:*:*:*:*:*:*
cpe:2.3:a:centrify:centrify_suite:2012:*:*:*:*:*:*:*
cpe:2.3:a:centrify:centrify_suite:2012.5:*:*:*:*:*:*:*
cpe:2.3:a:centrify:centrify_suite:2014.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:16

Type Values Removed Values Added
References () http://twitter.com/travemme/statuses/525298393971564544 - () http://twitter.com/travemme/statuses/525298393971564544 -
References () http://www.centrify.com/support/announcements.asp#20141014 - () http://www.centrify.com/support/announcements.asp#20141014 -
References () https://exploithub.com/centrify-data-leakage.html - () https://exploithub.com/centrify-data-leakage.html -

Information

Published : 2014-10-24 10:55

Updated : 2024-11-21 02:16


NVD link : CVE-2014-7298

Mitre link : CVE-2014-7298

CVE.ORG link : CVE-2014-7298


JSON object : View

Products Affected

centrify

  • directcontrol
  • centrify_suite
CWE
CWE-264

Permissions, Privileges, and Access Controls