NetBSD/FreeBSD Port Systrace Exit Routine Access Validation Privilege Escalation Vulnerability
BID:10320
Info
NetBSD/FreeBSD Port Systrace Exit Routine Access Validation Privilege Escalation Vulnerability
| Bugtraq ID: | 10320 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 11 2004 12:00AM |
| Updated: | May 11 2004 12:00AM |
| Credit: | Discovery is credited to Stefan Esser. |
| Vulnerable: |
Vladimir Kotal Systrace Port for FreeBSD 20040602 snapshot Vladimir Kotal Systrace Port for FreeBSD 20040309 snapshot Niels Provos Systrace 1.5 Niels Provos Systrace 1.4 Niels Provos Systrace 1.3 Niels Provos Systrace 1.2 Niels Provos Systrace 1.1 NetBSD NetBSD 2.0 |
| Not Vulnerable: |
NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 |
Discussion
NetBSD/FreeBSD Port Systrace Exit Routine Access Validation Privilege Escalation Vulnerability
A vulnerability has been reported that affects Systrace on NetBSD, as well as the FreeBSD port by Vladimir Kotal.
The source of the issue is insufficient access validation when a systraced process is restoring privileges.
This issue can be exploited by a local attacker to gain root privileges on a vulnerable system.
A vulnerability has been reported that affects Systrace on NetBSD, as well as the FreeBSD port by Vladimir Kotal.
The source of the issue is insufficient access validation when a systraced process is restoring privileges.
This issue can be exploited by a local attacker to gain root privileges on a vulnerable system.
Exploit / POC
NetBSD/FreeBSD Port Systrace Exit Routine Access Validation Privilege Escalation Vulnerability
The researcher who discovered this issue has developed working exploit code that is not publicly available or known to be circulating in the wild. The following exploit (netbsd_systrace.c) is alleged to be a working proof of concept; Symantec has neither verified the integrity or viability of this exploit.
The researcher who discovered this issue has developed working exploit code that is not publicly available or known to be circulating in the wild. The following exploit (netbsd_systrace.c) is alleged to be a working proof of concept; Symantec has neither verified the integrity or viability of this exploit.
Solution / Fix
NetBSD/FreeBSD Port Systrace Exit Routine Access Validation Privilege Escalation Vulnerability
Solution:
This issue has been addressed in the NetBSD CVS tree as of 2004/04/09. Other official fixes have not been released as of this writing.
NetBSD has released security advisory 2004-007 dealing with this issue. Please see the referenced advisory for more information as well as details on obtaining fixes.
Solution:
This issue has been addressed in the NetBSD CVS tree as of 2004/04/09. Other official fixes have not been released as of this writing.
NetBSD has released security advisory 2004-007 dealing with this issue. Please see the referenced advisory for more information as well as details on obtaining fixes.
References
NetBSD/FreeBSD Port Systrace Exit Routine Access Validation Privilege Escalation Vulnerability
References:
References:
- Systrace Homepage (Niels Provos)
- systrace port for FreeBSD (Vladimir Kotal)
- Advisory 04/2004: Net(Free)BSD Systrace local root vulnerabilitiy (Stefan Esser
)