RSBAC Jail SUID And SGID File Creation Vulnerability
BID:10640
Info
RSBAC Jail SUID And SGID File Creation Vulnerability
| Bugtraq ID: | 10640 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0667 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Brad Spengler originally disclosed this issue to the vendor. |
| Vulnerable: |
RSBAC RSBAC 1.2.3 RSBAC RSBAC 1.2.2 Gentoo Linux 1.4 |
| Not Vulnerable: | |
Discussion
RSBAC Jail SUID And SGID File Creation Vulnerability
The process jail feature of RSBAC reportedly improperly allows files to be created with SUID and SGID attributes.
These files can then be used to escalate the privileges inside the jail. This may allow for further attacks and possible system compromises.
Versions 1.2.2 and 1.2.3 are reported to be vulnerable to this issue. A patch has been released by the vendor.
The process jail feature of RSBAC reportedly improperly allows files to be created with SUID and SGID attributes.
These files can then be used to escalate the privileges inside the jail. This may allow for further attacks and possible system compromises.
Versions 1.2.2 and 1.2.3 are reported to be vulnerable to this issue. A patch has been released by the vendor.
Exploit / POC
RSBAC Jail SUID And SGID File Creation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RSBAC Jail SUID And SGID File Creation Vulnerability
Solution:
The vendor has released a patch dealing with this issue for version 1.2.3. Users of version 1.2.2 are urged to upgrade and apply this patch.
Gentoo Linux has released advisory GLSA 200407-02 addressing this and other issues. Please see the referenced advisory for further information about this issue and information on upgrading packages using emerge.
RSBAC RSBAC 1.2.3
Solution:
The vendor has released a patch dealing with this issue for version 1.2.3. Users of version 1.2.2 are urged to upgrade and apply this patch.
Gentoo Linux has released advisory GLSA 200407-02 addressing this and other issues. Please see the referenced advisory for further information about this issue and information on upgrading packages using emerge.
RSBAC RSBAC 1.2.3
-
RSBAC rsbac-bugfix-v1.2.3-3.diff
http://www.rsbac.org/download/bugfixes/v1.2.3/rsbac-bugfix-v1.2.3-3.di ff
References
RSBAC Jail SUID And SGID File Creation Vulnerability
References:
References:
- RSBAC Home Page (RSBAC)
- rsbac 1.2.3 jail security problems (Bencsath Boldizsar
)