Linux Man Malicious Cache File Creation Vulnerability
BID:2815
Info
Linux Man Malicious Cache File Creation Vulnerability
| Bugtraq ID: | 2815 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 04 2001 12:00AM |
| Updated: | Jun 04 2001 12:00AM |
| Credit: | Discovered by Luki R. <[email protected]> |
| Vulnerable: |
Redhat Linux 7.1 Redhat Linux 7.0 Redhat Linux 6.1 Redhat Linux 6.2 Debian Linux 2.2 Debian Linux 2.1 |
| Not Vulnerable: | |
Discussion
Linux Man Malicious Cache File Creation Vulnerability
A vulnerability exists in the 'man' system manual pager program.
It is possible for local users to cause man to cache files in the system cache directory from outside of the configured manual page hierarchy search path.
Combined with the behaviours of 'man' and 'mandb' or any other utilities which trust cache filenames, it may be possible to use this vulnerability to elevate privileges.
A vulnerability exists in the 'man' system manual pager program.
It is possible for local users to cause man to cache files in the system cache directory from outside of the configured manual page hierarchy search path.
Combined with the behaviours of 'man' and 'mandb' or any other utilities which trust cache filenames, it may be possible to use this vulnerability to elevate privileges.
Exploit / POC
Linux Man Malicious Cache File Creation Vulnerability
The 'mandebian.sh' and 'manredhat.sh' exploits have been made available by Luki R. <[email protected]>.
The 'mandebian.sh' and 'manredhat.sh' exploits have been made available by Luki R. <[email protected]>.
Solution / Fix
Linux Man Malicious Cache File Creation Vulnerability
Solution:
Removing the setuid bit from '/usr/lib/man-db/mandb' will eliminate the possibility of immediately gaining uid 'man'. It may also be advisable to remove the setuid bit from '/usr/lib/man-db/man' as well.
Vendor updates which rectify this issue are available:
Debian Linux 2.2
Solution:
Removing the setuid bit from '/usr/lib/man-db/mandb' will eliminate the possibility of immediately gaining uid 'man'. It may also be advisable to remove the setuid bit from '/usr/lib/man-db/man' as well.
Vendor updates which rectify this issue are available:
Debian Linux 2.2
-
Debian 2.2 alpha man-db_2.3.16-4_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/man- db_2.3.16-4_alpha.deb -
Debian 2.2 arm man-db_2.3.16-4_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/man-db _2.3.16-4_arm.deb -
Debian 2.2 i386 man-db_2.3.16-4_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/man-d b_2.3.16-4_i386.deb -
Debian 2.2 m68k man-db_2.3.16-4_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/man-d b_2.3.16-4_m68k.deb -
Debian 2.2 ppc man-db_2.3.16-4_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/ma n-db_2.3.16-4_powerpc.deb -
Debian 2.2 sparc man-db_2.3.16-4_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/man- db_2.3.16-4_sparc.deb
References
Linux Man Malicious Cache File Creation Vulnerability
References:
References: