Secunia Security Advisory - Marsh Ray has discovered a security issue in Intel C++ Compiler Professional Edition, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
9c45a95138daa8489cbef730947a2e480bf45a3cba8f2175026067389a9dc163
----------------------------------------------------------------------
Secunia CSI
+ Microsoft SCCM
-----------------------
= Extensive Patch Management
http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/
----------------------------------------------------------------------
TITLE:
Intel C++ Compiler Professional Edition for Linux Privilege
Escalation
SECUNIA ADVISORY ID:
SA39511
VERIFY ADVISORY:
http://secunia.com/advisories/39511/
DESCRIPTION:
Marsh Ray has discovered a security issue in Intel C++ Compiler
Professional Edition, which can be exploited by malicious, local
users to perform certain actions with escalated privileges.
The security issue is caused due to e.g. the "idbc" and "icc"
applications changing the permissions of the "/tmp/FLEXnet" directory
to world-writable in an insecure manner. This can be exploited to e.g.
change the access permissions of arbitrary files via symlink attacks.
The security issue is confirmed in Intel C++ Compiler Professional
Edition 11.1.069 on a Linux system. Other versions may also be
affected.
SOLUTION:
Restrict access to trusted users only.
PROVIDED AND/OR DISCOVERED BY:
Marsh Ray
ORIGINAL ADVISORY:
http://extendedsubset.com/?p=30
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------