Net-Acct Symbolic Link Vulnerability
BID:11125
Info
Net-Acct Symbolic Link Vulnerability
| Bugtraq ID: | 11125 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0851 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery of this vulnerability is credited to Stefan Nordhausen. |
| Vulnerable: |
Ulrich Callmeier Net-Acct 0.71 Ulrich Callmeier Net-Acct 0.7 Ulrich Callmeier Net-Acct 0.6 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha |
| Not Vulnerable: | |
Discussion
Net-Acct Symbolic Link Vulnerability
Net-Acct is reportedly affected by a symbolic link vulnerability. This issue is due to a design error that fails to properly verify files prior to writing to them.
This issue will allow an attacker to overwrite arbitrary files. Reportedly, this issue could be leveraged to facilitate privilege escalation.
Net-Acct is reportedly affected by a symbolic link vulnerability. This issue is due to a design error that fails to properly verify files prior to writing to them.
This issue will allow an attacker to overwrite arbitrary files. Reportedly, this issue could be leveraged to facilitate privilege escalation.
Exploit / POC
Net-Acct Symbolic Link Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Net-Acct Symbolic Link Vulnerability
Solution:
Debian Linux has released an advisory (DSA 559-1) along with fixes dealing with this issue. Please see the referenced advisory for more information.
The vendor has released a patch to address this issue:
Ulrich Callmeier Net-Acct 0.6
Ulrich Callmeier Net-Acct 0.7
Ulrich Callmeier Net-Acct 0.71
Solution:
Debian Linux has released an advisory (DSA 559-1) along with fixes dealing with this issue. Please see the referenced advisory for more information.
The vendor has released a patch to address this issue:
Ulrich Callmeier Net-Acct 0.6
-
Net-Acct net-acct-notempfiles.patch
http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
Ulrich Callmeier Net-Acct 0.7
-
Net-Acct net-acct-notempfiles.patch
http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
Ulrich Callmeier Net-Acct 0.71
-
Debian net-acct_0.71-5woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_alpha.deb -
Debian net-acct_0.71-5woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_arm.deb -
Debian net-acct_0.71-5woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_hppa.deb -
Debian net-acct_0.71-5woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_i386.deb -
Debian net-acct_0.71-5woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_ia64.deb -
Debian net-acct_0.71-5woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_m68k.deb -
Debian net-acct_0.71-5woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_mips.deb -
Debian net-acct_0.71-5woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_mipsel.deb -
Debian net-acct_0.71-5woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_powerpc.deb -
Debian net-acct_0.71-5woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_s390.deb -
Debian net-acct_0.71-5woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/n/net-acct/net-acct_0.71- 5woody1_sparc.deb -
Net-Acct net-acct-notempfiles.patch
http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
References
Net-Acct Symbolic Link Vulnerability
References:
References:
- Net-Acct Homepage (Net-Acct)
- Insecure Temporary File Creation Vulnerability in Net-Acct ("Jérôme" ATHIAS
)