SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
BID:15182
Info
SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
| Bugtraq ID: | 15182 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 24 2005 12:00AM |
| Updated: | Oct 24 2005 12:00AM |
| Credit: | Stefan Nordhausen reported this issue to the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 |
| Not Vulnerable: | |
Discussion
SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
The SUSE Linux 'permissions' package is susceptible to a local information disclosure vulnerability. This issue is due to improper handling of file permissions by the 'chkstat' utility.
This issue is due to the inherent insecurity of attempting to modify files contained in world-writable directories.
Local attackers may gain access to the contents of potentially sensitive files, aiding them in further attacks.
The SUSE Linux 'permissions' package is susceptible to a local information disclosure vulnerability. This issue is due to improper handling of file permissions by the 'chkstat' utility.
This issue is due to the inherent insecurity of attempting to modify files contained in world-writable directories.
Local attackers may gain access to the contents of potentially sensitive files, aiding them in further attacks.
Exploit / POC
SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
Solution:
The vendor has released advisory SUSE-SA:2005:062, along with fixes to address this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released advisory SUSE-SA:2005:062, along with fixes to address this issue. Please see the referenced advisory for further information.
References
SUSE Linux Permissions Package CHKSTAT Insecure Permissions Handling Vulnerability
References:
References: