Vulnerabilities > CVE-2006-3693 - Local Privilege Escalation vulnerability in Rocks Clusters

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
rocks-clusters
exploit available

Summary

Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call.

Vulnerable Configurations

Part Description Count
Application
Rocks_Clusters
1

Exploit-Db

  • descriptionRocks Clusters <= 4.1 (mount-loop) Local Root Exploit. CVE-2006-3693. Local exploit for linux platform
    idEDB-ID:2016
    last seen2016-01-31
    modified2006-07-15
    published2006-07-15
    reporterXavier de Leon
    sourcehttps://www.exploit-db.com/download/2016/
    titleRocks Clusters <= 4.1 mount-loop Local Root Exploit
  • descriptionRocks Clusters. CVE-2006-3693. Local exploit for linux platform
    idEDB-ID:2015
    last seen2016-01-31
    modified2006-07-15
    published2006-07-15
    reporterXavier de Leon
    sourcehttps://www.exploit-db.com/download/2015/
    titleRocks Clusters <= 4.1 - umount-loop Local Root Exploit