97416vdb entry
http://osvdb.org/97416 CVE-2013-4362
davfs2 1.4.6/1.4.7 - Local Privilege Escalation
Record summary
CVE-2013-4362 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBdavfs2 1.4.6/1.4.7 - Local Privilege EscalationExploitDB exploitby Lorenzo CantoniNot analyzed1 file
Repository PoCs
GitHubnotclement/Automatic-davfs2-1.4.6-1.4.7-Local-Privilege-EscalationRepository PoCby notclementStars: 2Not analyzed3 files
References
897417vdb entry
http://osvdb.org/97417 savannah.nongnu.orgConfirmation
http://savannah.nongnu.org/bugs?40034 [oss-security] 20130918 Re: CVE request: davfs2 - Unsecure use of system()mailing list
http://seclists.org/oss-sec/2013/q3/627 DSA-2765Vendor advisory
http://www.debian.org/security/2013/dsa-2765 62445vdb entry
http://www.securityfocus.com/bid/62445 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-4362 GLSA-201612-02Vendor advisory
https://security.gentoo.org/glsa/201612-02