AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2015-7723/ | third party advisory exploit |
http://packetstormsecurity.com/files/134121/AMD-fglrx-driver-14.4.2-Privilege-Escalation.html | third party advisory vdb entry exploit |
http://seclists.org/fulldisclosure/2015/Oct/104 | vdb entry mailing list |
http://www.securityfocus.com/archive/1/536783/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/77357 | third party advisory vdb entry |