Secunia Security Advisory - A vulnerability has been reported in Speedtouch USB Driver, which potentially can be exploited by malicious, local users to gain escalated privileges.
76aee022b1a8f1207b62499507352f2a7c3a5d59d5d9b0fed33a0c8447865092
TITLE:
Speedtouch USB Driver Privilege Escalation Vulnerability
SECUNIA ADVISORY ID:
SA12916
VERIFY ADVISORY:
http://secunia.com/advisories/12916/
CRITICAL:
Less critical
IMPACT:
Privilege escalation
WHERE:
Local system
SOFTWARE:
Speedtouch USB driver 1.x
http://secunia.com/product/4124/
DESCRIPTION:
A vulnerability has been reported in Speedtouch USB Driver, which
potentially can be exploited by malicious, local users to gain
escalated privileges.
The vulnerability is caused due to an unspecified format string
errors in "modem_run", "pppoa2", and "pppoa3".
Successful exploitation may potentially allow execution of arbitrary
code with escalated privileges.
SOLUTION:
Update to version 1.3.1.
http://sourceforge.net/project/showfiles.php?group_id=32758&package_id=28264&release_id=271734
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Max Vozeler.
ORIGINAL ADVISORY:
http://speedtouch.sourceforge.net/index.php?/news.en.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------