Sendfile Local Arbitrary Command Execution as Group 0 Vulnerability
BID:2631
Info
Sendfile Local Arbitrary Command Execution as Group 0 Vulnerability
| Bugtraq ID: | 2631 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 20 2001 12:00AM |
| Updated: | Apr 20 2001 12:00AM |
| Credit: | Reportedly discovered by Colin Phipps and Daniel Kobras. |
| Vulnerable: |
Sendfile Sendfile 2.1 Sendfile Sendfile 1.6 Sendfile Sendfile 1.5 Sendfile Sendfile 1.4 |
| Not Vulnerable: | |
Discussion
Sendfile Local Arbitrary Command Execution as Group 0 Vulnerability
A vulnerability exists in the Sendfile asynchronous file transfer daemon.
Failure by the sendfile daemon (sendfiled) to validate a user-supplied configuration value could allow a local user to execute arbitrary code and gain group 0 privileges.
This may lead to a further compromise on some systems.
Update: There is a serialization error which can result in privileges not being dropped properly. In conjunction with such behaviour, this vulnerability can be used to obtain user root privileges. If exploited, it would be a complete system compromise.
A vulnerability exists in the Sendfile asynchronous file transfer daemon.
Failure by the sendfile daemon (sendfiled) to validate a user-supplied configuration value could allow a local user to execute arbitrary code and gain group 0 privileges.
This may lead to a further compromise on some systems.
Update: There is a serialization error which can result in privileges not being dropped properly. In conjunction with such behaviour, this vulnerability can be used to obtain user root privileges. If exploited, it would be a complete system compromise.
Solution / Fix
Sendfile Local Arbitrary Command Execution as Group 0 Vulnerability
Solution:
**NOTE**: Certain fixes that are available may not completely eliminate vulnerability in Sendfile.
Users are advised to download the upgraded package directly from the Sendfile distribution site (see below):
Sendfile Sendfile 1.4
Sendfile Sendfile 1.5
Sendfile Sendfile 1.6
Sendfile Sendfile 2.1
Solution:
**NOTE**: Certain fixes that are available may not completely eliminate vulnerability in Sendfile.
Users are advised to download the upgraded package directly from the Sendfile distribution site (see below):
Sendfile Sendfile 1.4
-
Sendfile Sendfile-20010216
ftp://ftp.belwue.de/pub/unix/sendfile/current/sendfile-20010216.tar.gz
Sendfile Sendfile 1.5
-
Sendfile Sendfile-20010216
ftp://ftp.belwue.de/pub/unix/sendfile/current/sendfile-20010216.tar.gz
Sendfile Sendfile 1.6
-
Sendfile Sendfile-20010216
ftp://ftp.belwue.de/pub/unix/sendfile/current/sendfile-20010216.tar.gz
Sendfile Sendfile 2.1
-
Sendfile Sendfile-20010216
ftp://ftp.belwue.de/pub/unix/sendfile/current/sendfile-20010216.tar.gz
References
Sendfile Local Arbitrary Command Execution as Group 0 Vulnerability
References:
References:
- Sendfile Homepage (in English) (Ulli Horlacher)