LessTif Debug Feature Local Arbitrary File Creation Vulnerability
BID:19430
CVE-2006-4124 |Info
LessTif Debug Feature Local Arbitrary File Creation Vulnerability
| Bugtraq ID: | 19430 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-4124 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Oct 20 2006 10:33PM |
| Credit: | [email protected] discovered this issue. |
| Vulnerable: |
Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Lesstif Lesstif 0.93.94 |
| Not Vulnerable: | |
Discussion
LessTif Debug Feature Local Arbitrary File Creation Vulnerability
LessTif is prone to a local arbitrary file-creation vulnerability. This issue is exposed when an application using the affected library runs with setuid-privileges.
This issue presents itself only when the library is compiled without the 'LESSTIF_PRODUCTION' definition. This occurs when the '--enable-production' configuration option is not selected when the package is built.
When used in conjunction with the 'mtink' binary, exploiting this issue has been demonstrated to gain superuser privileges.
LessTif version 0.93.94 is vulnerable to this issue; other versions may also be affected.
LessTif is prone to a local arbitrary file-creation vulnerability. This issue is exposed when an application using the affected library runs with setuid-privileges.
This issue presents itself only when the library is compiled without the 'LESSTIF_PRODUCTION' definition. This occurs when the '--enable-production' configuration option is not selected when the package is built.
When used in conjunction with the 'mtink' binary, exploiting this issue has been demonstrated to gain superuser privileges.
LessTif version 0.93.94 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
LessTif Debug Feature Local Arbitrary File Creation Vulnerability
The following exploit code is available to demonstrate this issue:
The following exploit code is available to demonstrate this issue:
Solution / Fix
LessTif Debug Feature Local Arbitrary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] mailto:[email protected]:[email protected].
Please see references for more information and vendor advisories.
Lesstif Lesstif 0.93.94
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] mailto:[email protected]:[email protected].
Please see references for more information and vendor advisories.
Lesstif Lesstif 0.93.94
-
Mandriva lesstif-0.93.94-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-0.93.94-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-0.93.94-4.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-0.93.94-4.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-clients-0.93.94-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-clients-0.93.94-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-clients-0.93.94-4.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-clients-0.93.94-4.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-devel-0.93.94-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-devel-0.93.94-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-devel-0.93.94-4.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-devel-0.93.94-4.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-mwm-0.93.94-1.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-mwm-0.93.94-1.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-mwm-0.93.94-4.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lesstif-mwm-0.93.94-4.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64lesstif1-0.93.94-4.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64lesstif2-0.93.94-4.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva liblesstif1-0.93.94-4.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva liblesstif2-0.93.94-4.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
References
LessTif Debug Feature Local Arbitrary File Creation Vulnerability
References:
References:
- Lesstif Project Home Page (Lesstif)