Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
BID:18108
CVE-2006-2607 |Info
Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
| Bugtraq ID: | 18108 |
| Class: | Design Error |
| CVE: |
CVE-2006-2607 |
| Remote: | No |
| Local: | Yes |
| Published: | May 25 2006 12:00AM |
| Updated: | Jun 01 2009 07:49PM |
| Credit: | Discovery is credited to Roman Veretelnikov. |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 TransSoft Broker FTP Server 8.0 TransSoft Broker FTP Server 7.0 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 10.1 Redhat Fedora Core4 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Paul Vixie Vixie Cron 4.1 Gentoo Linux Avaya Messaging Storage Server MM3.0 |
| Not Vulnerable: | |
Discussion
Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
Vixie cron is prone to a local privilege-escalation vulnerability because the application fails to properly drop superuser privileges in certain circumstances when executing jobs.
This issue allows local attackers who have been authorized to execute cron jobs to run arbitrary commands with superuser privileges. This facilitates the complete compromise of affected computers.
Vixie cron 4.1 is vulnerable when used in conjunction with pam_limits. Other versions may also be affected.
Vixie cron is prone to a local privilege-escalation vulnerability because the application fails to properly drop superuser privileges in certain circumstances when executing jobs.
This issue allows local attackers who have been authorized to execute cron jobs to run arbitrary commands with superuser privileges. This facilitates the complete compromise of affected computers.
Vixie cron 4.1 is vulnerable when used in conjunction with pam_limits. Other versions may also be affected.
Exploit / POC
Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
To trigger this issue, attackers use the affected cron utility in a normal manner.
To trigger this issue, attackers use the affected cron utility in a normal manner.
Solution / Fix
Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 9.04 sparc
Ubuntu Ubuntu Linux 9.04 powerpc
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 8.10 lpia
Ubuntu Ubuntu Linux 6.06 LTS amd64
Ubuntu Ubuntu Linux 9.04 i386
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 9.04 lpia
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 9.04 amd64
Ubuntu Ubuntu Linux 8.10 amd64
Paul Vixie Vixie Cron 4.1
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu cron_3.0pl1-100ubuntu2.1_powerpc.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-100ubuntu2.1_powe rpc.deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu cron_3.0pl1-104+ubuntu5.1_powerpc.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-104+ubuntu5.1_pow erpc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu cron_3.0pl1-100ubuntu2.1_sparc.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-100ubuntu2.1_spar c.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu cron_3.0pl1-104+ubuntu5.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-104+ubu ntu5.1_i386.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu cron_3.0pl1-92ubuntu1.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-92ubunt u1.1_sparc.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu cron_3.0pl1-100ubuntu2.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-100ubun tu2.1_amd64.deb
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu cron_3.0pl1-92ubuntu1.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-92ubunt u1.1_powerpc.deb
Ubuntu Ubuntu Linux 9.04 sparc
-
Ubuntu cron_3.0pl1-105ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-105ubuntu1.1_spar c.deb
Ubuntu Ubuntu Linux 9.04 powerpc
-
Ubuntu cron_3.0pl1-105ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-105ubuntu1.1_powe rpc.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu cron_3.0pl1-100ubuntu2.1_lpia.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-100ubuntu2.1_lpia .deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu cron_3.0pl1-92ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-92ubunt u1.1_i386.deb
Ubuntu Ubuntu Linux 8.10 lpia
-
Ubuntu cron_3.0pl1-104+ubuntu5.1_lpia.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-104+ubuntu5.1_lpi a.deb
Ubuntu Ubuntu Linux 6.06 LTS amd64
-
Ubuntu cron_3.0pl1-92ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-92ubunt u1.1_amd64.deb
Ubuntu Ubuntu Linux 9.04 i386
-
Ubuntu cron_3.0pl1-105ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-105ubun tu1.1_i386.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu cron_3.0pl1-104+ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-104+ubuntu5.1_spa rc.deb
Ubuntu Ubuntu Linux 9.04 lpia
-
Ubuntu cron_3.0pl1-105ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/c/cron/cron_3.0pl1-105ubuntu1.1_lpia .deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu cron_3.0pl1-100ubuntu2.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-100ubun tu2.1_i386.deb
Ubuntu Ubuntu Linux 9.04 amd64
-
Ubuntu cron_3.0pl1-105ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-105ubun tu1.1_amd64.deb
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu cron_3.0pl1-104+ubuntu5.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/c/cron/cron_3.0pl1-104+ubu ntu5.1_amd64.deb
Paul Vixie Vixie Cron 4.1
-
SuSE cron-4.1-14.2.i586.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/cron-4.1-14.2.i58 6.rpm -
SuSE cron-4.1-14.2.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/cron-4.1-14.2.x 86_64.rpm -
SuSE cron-4.1-20.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/cron-4.1-20.2.i58 6.rpm -
SuSE cron-4.1-20.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/cron-4.1-20.2.x 86_64.rpm -
SuSE cron-4.1-26.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/cron-4.1-26.2.i5 86.rpm -
SuSE cron-4.1-26.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/cron-4.1-26.2.ppc .rpm -
SuSE cron-4.1-26.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/cron-4.1-26.2. x86_64.rpm -
SuSE cron-4.1-45.3.i586.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/cron-4.1-45.3.i586.rp m -
SuSE cron-4.1-45.3.ppc.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/cron-4.1-45.3.ppc.rpm -
SuSE cron-4.1-45.3.x86_64.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/cron-4.1-45.3.x86_6 4.rpm
References
Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
References:
References:
- Bugzilla Bug 178431 �?? CVE-2006-2607 Jobs start from root when pam_limits enabled (Red Hat)
- RHSA-2006:0539-9 - vixie-cron security update (Red Hat)
- rPSA-2006-0082-1 vixie-cron ("Justin M. Forbes"
) - vixie-cron security update (RHSA-2006-0539) (Avaya)