SCPOnly Multiple Local Vulnerabilities
BID:16051
Info
SCPOnly Multiple Local Vulnerabilities
| Bugtraq ID: | 16051 |
| Class: | Design Error |
| CVE: |
CVE-2005-4532 CVE-2005-4533 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2005 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | The first issue was discovered by Max Vozeler. The second issue was discovered by Pekka Pessi. |
| Vulnerable: |
scponly scponly 4.1 scponly scponly 4.0 scponly scponly 3.11 scponly scponly 3.9 scponly scponly 3.8 scponly scponly 3.5 scponly scponly 3.0 scponly scponly 2.4 scponly scponly 2.3 scponly scponly 2.1 scponly scponly 2.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
scponly scponly 4.2 |
Discussion
SCPOnly Multiple Local Vulnerabilities
The 'scponly' program is prone to multiple local vulnerabilities. These issues can allow local attackers to gain elevated privileges.
The application is affected by a design error affecting the 'scponlyc' binary.
An attacker can also issue malicious command-line arguments to 'rsync' or scp to execute arbitrary applications with elevated privileges.
Successful exploitation of these issues can facilitate a complete compromise.
The 'scponly' program is prone to multiple local vulnerabilities. These issues can allow local attackers to gain elevated privileges.
The application is affected by a design error affecting the 'scponlyc' binary.
An attacker can also issue malicious command-line arguments to 'rsync' or scp to execute arbitrary applications with elevated privileges.
Successful exploitation of these issues can facilitate a complete compromise.
Exploit / POC
SCPOnly Multiple Local Vulnerabilities
Exploit code is not required.
Exploit code is not required.
Solution / Fix
SCPOnly Multiple Local Vulnerabilities
Solution:
Please see the referenced vendor advisories for details on obtaining and applying fixes.
The vendor has released scponly 4.2 to address these issues.
scponly scponly 2.0
scponly scponly 2.1
scponly scponly 2.3
scponly scponly 2.4
scponly scponly 3.0
scponly scponly 3.11
scponly scponly 3.5
scponly scponly 3.8
scponly scponly 3.9
scponly scponly 4.0
scponly scponly 4.1
Solution:
Please see the referenced vendor advisories for details on obtaining and applying fixes.
The vendor has released scponly 4.2 to address these issues.
scponly scponly 2.0
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 2.1
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 2.3
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 2.4
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 3.0
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 3.11
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 3.5
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 3.8
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 3.9
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 4.0
-
Debian scponly_4.0-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_alpha.deb -
Debian scponly_4.0-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_amd64.deb -
Debian scponly_4.0-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_arm.deb -
Debian scponly_4.0-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_hppa.deb -
Debian scponly_4.0-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_i386.deb -
Debian scponly_4.0-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_ia64.deb -
Debian scponly_4.0-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_m68k.deb -
Debian scponly_4.0-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_mips.deb -
Debian scponly_4.0-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/scponly/scponly_4.0-1sa rge1_mipsel.deb -
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
scponly scponly 4.1
-
scponly scponly-4.2.tgz
http://sublimation.org/scponly/scponly-4.2.tgz
References
SCPOnly Multiple Local Vulnerabilities
References:
References:
- dec 2005 scponly 4.2 release (Sublimation.org)
- scponly Homepage (Sublimation.org)