Suid Wrapper Buffer Overflow Vulnerability
BID:2837
Info
Suid Wrapper Buffer Overflow Vulnerability
| Bugtraq ID: | 2837 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 07 2001 12:00AM |
| Updated: | Jun 07 2001 12:00AM |
| Credit: | Reported to Bugtraq by dex <[email protected]> on June 6, 2001. |
| Vulnerable: |
kosch suid wrapper 1.1.1 |
| Not Vulnerable: | |
Discussion
Suid Wrapper Buffer Overflow Vulnerability
A boundary condition error exists in suid wrapper (or 'su-wrapper.')
The overflow occurs when a string exceeding approximately 1032 characters is given as the first argument when the program is run. Because the program is installed setuid root, it may be possible for local users to execute arbitrary code/commands with those privileges.
A boundary condition error exists in suid wrapper (or 'su-wrapper.')
The overflow occurs when a string exceeding approximately 1032 characters is given as the first argument when the program is run. Because the program is installed setuid root, it may be possible for local users to execute arbitrary code/commands with those privileges.
Exploit / POC
Solution / Fix
Suid Wrapper Buffer Overflow Vulnerability
Solution:
An unsupported, untested fix has been provided by Guy Tsafnat <[email protected]>. This patch is not vendor-supported:
kosch suid wrapper 1.1.1
Solution:
An unsupported, untested fix has been provided by Guy Tsafnat <[email protected]>. This patch is not vendor-supported:
kosch suid wrapper 1.1.1
-
Guy Tsafnat su-wrapper 1.1.1
http://www.securityfocus.com/data/vulnerabilities/patches/su-wrapper.c