Learn about CVE-2019-7656, a privilege escalation vulnerability in Wowza Streaming Engine versions 4.8.0 and earlier, allowing unprivileged Linux users to gain root privileges. Find out how to mitigate and prevent this security issue.
Wowza Streaming Engine versions 4.8.0 and earlier contain a vulnerability that allows unprivileged Linux users to escalate their privileges to root. The issue has been resolved in version 4.8.5.
Understanding CVE-2019-7656
This CVE involves a privilege escalation vulnerability in Wowza Streaming Engine versions 4.8.0 and earlier, enabling unprivileged users to gain root privileges.
What is CVE-2019-7656?
The vulnerability in Wowza Streaming Engine versions 4.8.0 and earlier allows any Linux user without privileges to elevate their privileges to root by exploiting overly relaxed permissions on core program files.
The Impact of CVE-2019-7656
The vulnerability enables attackers to insert a malicious payload into specific files, granting them root privileges equivalent to the Wowza server. This could lead to unauthorized access and control of the system.
Technical Details of CVE-2019-7656
This section provides technical details about the vulnerability.
Vulnerability Description
The installer of Wowza Streaming Engine sets overly relaxed permissions on core program files in /usr/local/WowzaStreamingEngine/bin/*, allowing unprivileged users to escalate their privileges to root by injecting a malicious payload.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit the vulnerability by inserting a malicious payload into core program files, such as /usr/local/WowzaStreamingEngine/bin/tune.sh, granting them root privileges.
Mitigation and Prevention
Protect your system from CVE-2019-7656 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates