BestCrypt Arbitrary Privileged Program Execution Vulnerability
BID:2820
Info
BestCrypt Arbitrary Privileged Program Execution Vulnerability
| Bugtraq ID: | 2820 |
| Class: | Environment Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 05 2001 12:00AM |
| Updated: | Jun 05 2001 12:00AM |
| Credit: | Discovered by Joel Eriksson <[email protected]>. |
| Vulnerable: |
Jetico BestCrypt 0.7 |
| Not Vulnerable: | |
Discussion
BestCrypt Arbitrary Privileged Program Execution Vulnerability
BestCrypt is an encryption product that allows users to create encrypted loopback filesystems.
A vulnerability exists in the 'bctool' command-line interface program used with BestCrypt. When 'fsck' is executed for a specific filesystem type, it attempts to execute the 'fsck' utility appropriate for the specified filesystem. It does so relying on the PATH environment variable.
Attackers can use this vulnerability to execute an arbitrary program with effective user 'root' privileges.
BestCrypt is an encryption product that allows users to create encrypted loopback filesystems.
A vulnerability exists in the 'bctool' command-line interface program used with BestCrypt. When 'fsck' is executed for a specific filesystem type, it attempts to execute the 'fsck' utility appropriate for the specified filesystem. It does so relying on the PATH environment variable.
Attackers can use this vulnerability to execute an arbitrary program with effective user 'root' privileges.
Exploit / POC
BestCrypt Arbitrary Privileged Program Execution Vulnerability
There is no exploit required. See discussion.
There is no exploit required. See discussion.
Solution / Fix
BestCrypt Arbitrary Privileged Program Execution Vulnerability
Solution:
This issue has been resolved in version 0.8 and greater:
Jetico BestCrypt 0.7
Solution:
This issue has been resolved in version 0.8 and greater:
Jetico BestCrypt 0.7
-
Jetico BestCrypt 0.8
http://www.jetico.com/download.htm