HP-UX setrlimit() Incorrect Core Processing Vulnerability
BID:3416
Info
HP-UX setrlimit() Incorrect Core Processing Vulnerability
| Bugtraq ID: | 3416 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 02 2001 12:00AM |
| Updated: | Jul 02 2001 12:00AM |
| Credit: | First published in HP Security Advisory HPSBUX0107-156. |
| Vulnerable: |
HP HP-UX (VVOS) 11.0.4 HP HP-UX (VVOS) 10.24 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.26 HP HP-UX 10.20 HP HP-UX 10.1 0 HP HP-UX 10.0 1 |
| Not Vulnerable: | |
Discussion
HP-UX setrlimit() Incorrect Core Processing Vulnerability
HP-UX contains a vulnerability in it's implementation of setrlimit().
After a setuid process drops privileges, limits placed core file generation via setrlimit() are not enforced. If an attacker causes the process to dump core, it will, even if the size is greater than that set as the limit.
An attacker could exploit this to create core files that consume excessive disk space.
It may also be possible to attach to setuid processes that have dropped privileges with a debugger. If this is possible, attackers may be able to read memory contents and access possibly sensitive information. This is not yet verified and may warrant an independent vulnerability database record.
HP-UX contains a vulnerability in it's implementation of setrlimit().
After a setuid process drops privileges, limits placed core file generation via setrlimit() are not enforced. If an attacker causes the process to dump core, it will, even if the size is greater than that set as the limit.
An attacker could exploit this to create core files that consume excessive disk space.
It may also be possible to attach to setuid processes that have dropped privileges with a debugger. If this is possible, attackers may be able to read memory contents and access possibly sensitive information. This is not yet verified and may warrant an independent vulnerability database record.
Exploit / POC
HP-UX setrlimit() Incorrect Core Processing Vulnerability
There is no exploit required, this can likely be exploited at a shell prompt.
There is no exploit required, this can likely be exploited at a shell prompt.
Solution / Fix
HP-UX setrlimit() Incorrect Core Processing Vulnerability
Solution:
HP has released fixes:
HP HP-UX 10.0 1
HP HP-UX 10.1 0
HP HP-UX 10.20
HP HP-UX (VVOS) 10.24
HP HP-UX 10.26
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0.4
HP HP-UX 11.11
Solution:
HP has released fixes:
HP HP-UX 10.0 1
HP HP-UX 10.1 0
HP HP-UX 10.20
HP HP-UX (VVOS) 10.24
HP HP-UX 10.26
HP HP-UX 11.0
-
HP PHKL_23628
-
HP PHKL_28180
http://itrc.hp.com
HP HP-UX (VVOS) 11.0.4
HP HP-UX 11.11
References
HP-UX setrlimit() Incorrect Core Processing Vulnerability
References:
References:
- HP IT Resource Center (for Europe) (HP IT Resource Center)
- HP IT Resource Center (for US, Canada, Asia-Pacific, & Latin-America) (HP IT Resource Center)