CHFN User Modification Privilege Escalation Vulnerability
BID:15314
Info
CHFN User Modification Privilege Escalation Vulnerability
| Bugtraq ID: | 15314 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3503 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 04 2005 12:00AM |
| Updated: | Nov 15 2007 12:37AM |
| Credit: | This issue was announced in the referenced SUSE security advisory. Thomas Gerisch is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 shadow shadow 4.0.3 Salvatore Valente chfn S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Enterprise Server for S/390 9.0 pwdutils pwdutils 3.0.4 pwdutils pwdutils 2.6.96 pwdutils pwdutils 2.6.90 pwdutils pwdutils 2.6.4 pwdutils pwdutils 2.6.3 |
| Not Vulnerable: | |
Discussion
CHFN User Modification Privilege Escalation Vulnerability
The 'chfn' utility is prone to a privilege-escalation vulnerability because it fails to properly sanitize user-supplied input.
A local attacker can exploit this vulnerability to escalate privileges to that of the superuser account.
The 'chfn' utility is prone to a privilege-escalation vulnerability because it fails to properly sanitize user-supplied input.
A local attacker can exploit this vulnerability to escalate privileges to that of the superuser account.
Exploit / POC
CHFN User Modification Privilege Escalation Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An example script demonstrating this issue is provided by Hunger <[email protected]>:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An example script demonstrating this issue is provided by Hunger <[email protected]>:
Solution / Fix
CHFN User Modification Privilege Escalation Vulnerability
Solution:
Please see the referenced advisory for more information.
pwdutils pwdutils 2.6.3
pwdutils pwdutils 2.6.90
pwdutils pwdutils 2.6.96
pwdutils pwdutils 3.0.4
shadow shadow 4.0.3
Solution:
Please see the referenced advisory for more information.
pwdutils pwdutils 2.6.3
-
SUSE pwdutils-2.6.4-2.18.3.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/pwdutils-2.6.4-2. 18.3.i586.rpm -
SUSE pwdutils-2.6.4-2.18.3.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/pwdutils-2.6. 4-2.18.3.x86_64.rpm
pwdutils pwdutils 2.6.90
-
SUSE pwdutils-2.6.90-6.2.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/pwdutils-2.6.90 -6.2.x86_64.rpm
pwdutils pwdutils 2.6.96
-
SUSE pwdutils-2.6.96-4.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/pwdutils-2.6.96-4 .2.i586.rpm -
SUSE pwdutils-2.6.96-4.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/pwdutils-2.6.96 -4.2.x86_64.rpm
pwdutils pwdutils 3.0.4
-
SUSE pwdutils-3.0.4-4.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/pwdutils-3.0.4-4 .2.i586.rpm -
SUSE pwdutils-3.0.4-4.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/pwdutils-3.0.4 -4.2.x86_64.rpm
shadow shadow 4.0.3
-
SUSE pwdutils-3.0.4-4.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/pwdutils-3.0.4-4. 2.ppc.rpm -
SUSE shadow-4.0.3-267.i586.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/shadow-4.0.3-267. i586.rpm -
SUSE shadow-4.0.3-267.x86_64.rpm
SuSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/shadow-4.0.3- 267.x86_64.rpm
References
CHFN User Modification Privilege Escalation Vulnerability
References:
References: