SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
BID:16765
Info
SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
| Bugtraq ID: | 16765 |
| Class: | Design Error |
| CVE: |
CVE-2005-2934 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 21 2006 12:00AM |
| Updated: | May 31 2006 10:33PM |
| Credit: | The original discoverer of this issue wishes to remain anonymous. |
| Vulnerable: |
SCO Unixware 7.1.4 SCO Unixware 7.1.3 |
| Not Vulnerable: | |
Discussion
SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
SCO UnixWare is prone to a local privilege-escalation vulnerability.
This issue allows local attackers to 'ptrace' privileged processes. Attackers may call arbitrary system calls, and then alter the behavior of the traced process, leading to a full system compromise.
SCO UnixWare 7.1.3 and 7.1.4 are vulnerable.
SCO UnixWare is prone to a local privilege-escalation vulnerability.
This issue allows local attackers to 'ptrace' privileged processes. Attackers may call arbitrary system calls, and then alter the behavior of the traced process, leading to a full system compromise.
SCO UnixWare 7.1.3 and 7.1.4 are vulnerable.
Exploit / POC
SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
Although an exploit as such isn't required to trigger this issue, attackers may need to create an application to use the 'ptrace()' functionality to execute arbitrary code in a setuid-superuser application.
A proof-of-concept example is available:
Although an exploit as such isn't required to trigger this issue, attackers may need to create an application to use the 'ptrace()' functionality to execute arbitrary code in a setuid-superuser application.
A proof-of-concept example is available:
Solution / Fix
SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the referenced advisory for further information on obtaining and installing fixes.
SCO Unixware 7.1.3
SCO Unixware 7.1.4
Solution:
The vendor has released an advisory and fixes to address this issue. Please see the referenced advisory for further information on obtaining and installing fixes.
SCO Unixware 7.1.3
-
SCO SCOSA-2006.9
UnixWare 7.1.3
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.9
SCO Unixware 7.1.4
-
SCO SCOSA-2006.9
UnixWare 7.1.3
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.9
References
SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
References:
References:
- UnixWare Product Homepage (Caldera Systems)
- iDefense Security Advisory 02.24.06: SCO Unixware Setuid ptrace Local Privilege (labs-no-reply
)