RedHat Linux restore Insecure Environment Variables Vulnerability
BID:1914
Info
RedHat Linux restore Insecure Environment Variables Vulnerability
| Bugtraq ID: | 1914 |
| Class: | Access Validation Error |
| CVE: |
CVE-2000-1125 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 03 2000 12:00AM |
| Updated: | Jul 11 2009 03:56AM |
| Credit: | This vulnerability was first publicly announced by fish stiqz <[email protected]> on November 4, 2000. |
| Vulnerable: |
Redhat restore 0.4 b15 |
| Not Vulnerable: | |
Discussion
RedHat Linux restore Insecure Environment Variables Vulnerability
restore is a program for backup and recovery procedures, distributed with the RedHat Linux Operating System. A vulnerability exists that could allow a user elevated permissions.
The problem occurs in the RSH environment variable. restore is dependent upon this environment variable for execution. It is possible to set this variable PATH to that of an executable, and then execute restore. This will result in the executable in the RSH environment variable being run with an EUID of 0. Exploitation of this vulnerability by a malicious user can result in root compromise.
restore is a program for backup and recovery procedures, distributed with the RedHat Linux Operating System. A vulnerability exists that could allow a user elevated permissions.
The problem occurs in the RSH environment variable. restore is dependent upon this environment variable for execution. It is possible to set this variable PATH to that of an executable, and then execute restore. This will result in the executable in the RSH environment variable being run with an EUID of 0. Exploitation of this vulnerability by a malicious user can result in root compromise.
Exploit / POC
RedHat Linux restore Insecure Environment Variables Vulnerability
This exploit was first made public by fish stiqz <[email protected]> on November 4, 2000.
This exploit was first made public by fish stiqz <[email protected]> on November 4, 2000.
Solution / Fix
RedHat Linux restore Insecure Environment Variables Vulnerability
References
RedHat Linux restore Insecure Environment Variables Vulnerability
References:
References: