RedHat Setserial Init Script Predictable Temporary File Vulnerability
BID:3367
Info
RedHat Setserial Init Script Predictable Temporary File Vulnerability
| Bugtraq ID: | 3367 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 26 2001 12:00AM |
| Updated: | Sep 26 2001 12:00AM |
| Credit: | This vulnerability was announced in a Red Hat Security Advisory on September 26, 2001. |
| Vulnerable: |
Redhat Linux 7.1 |
| Not Vulnerable: | |
Discussion
RedHat Setserial Init Script Predictable Temporary File Vulnerability
Red Hat Linux is a freely available clone of the UNIX Operating System, distributed by Red Hat Incorporated.
A problem has been discovered in the distribution that could lead to a race condition. If a user has recompiled their kernel and enabled modular serial support, and copied the rc.serial script to /etc/rc.d/init.d/serial, they're vulnerable to a race condition error. The serial init script creates temporary files insecurely.
This could allow a local user to overwrite system files, causing a denial of service, and potentially result in elevated privileges.
Red Hat Linux is a freely available clone of the UNIX Operating System, distributed by Red Hat Incorporated.
A problem has been discovered in the distribution that could lead to a race condition. If a user has recompiled their kernel and enabled modular serial support, and copied the rc.serial script to /etc/rc.d/init.d/serial, they're vulnerable to a race condition error. The serial init script creates temporary files insecurely.
This could allow a local user to overwrite system files, causing a denial of service, and potentially result in elevated privileges.
Exploit / POC
RedHat Setserial Init Script Predictable Temporary File Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RedHat Setserial Init Script Predictable Temporary File Vulnerability
Solution:
Upgrade setserial to the latest version after 2.17-4.
Solution:
Upgrade setserial to the latest version after 2.17-4.
References
RedHat Setserial Init Script Predictable Temporary File Vulnerability
References:
References: