AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/134120/AMD-fglrx-driver-15.7-Privilege-Escalation.html | exploit vdb entry third party advisory |
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2015-7724/ | third party advisory exploit |
http://www.securityfocus.com/archive/1/536782/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/77361 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2015/Oct/103 | mailing list vdb entry third party advisory |