gkermit setgid uucp Vulnerability
BID:1383
Info
gkermit setgid uucp Vulnerability
| Bugtraq ID: | 1383 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Jun 21 2000 12:00AM |
| Updated: | Jun 21 2000 12:00AM |
| Credit: | Posted to Bugtraq on Jun 21, 2000 by Michal Zalewski <[email protected]> |
| Vulnerable: |
Redhat kermit 1.0 -3 |
| Not Vulnerable: | |
Discussion
gkermit setgid uucp Vulnerability
The gkermit binary supplied with Redhat Linux (released after February 27, 2000) is setgid uucp. gkermit can read/write/append files with a gid of uucp, such as /etc/uucp/passwd and several /dev entries. Malicious use of gkermit is dangerous on systems running uucp.
The gkermit binary supplied with Redhat Linux (released after February 27, 2000) is setgid uucp. gkermit can read/write/append files with a gid of uucp, such as /etc/uucp/passwd and several /dev entries. Malicious use of gkermit is dangerous on systems running uucp.
Exploit / POC
gkermit setgid uucp Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].