Berkeley Parallel Make Shell Definition Format String Vulnerability
BID:3572
Info
Berkeley Parallel Make Shell Definition Format String Vulnerability
| Bugtraq ID: | 3572 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 21 2001 12:00AM |
| Updated: | Nov 21 2001 12:00AM |
| Credit: | This vulnerability was first announced to Bugtraq by Paul Starzetz <[email protected]> on November 21, 2001. |
| Vulnerable: |
SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 alpha SuSE Linux 6.4 |
| Not Vulnerable: | |
Discussion
Berkeley Parallel Make Shell Definition Format String Vulnerability
Parallel Make (pmake) is a freely available version of the make program, originally distributed with Berkeley Unix. It is designed to execute Makefiles and build programs.
pmake is not typically setuid root, although some Linux distributions default to installing it this way. When a Makefile is executed by pmake, certain user-defined variables can be set in the Makefile by the user. One such variable is the shell definition variable, or .SHELL. By supplying a format string in the check= field of the .SHELL variable, it is possible to write to an arbitrary memory address of the program. This could result in the overwriting of the return address, and execution of arbitrary code with root privileges.
Parallel Make (pmake) is a freely available version of the make program, originally distributed with Berkeley Unix. It is designed to execute Makefiles and build programs.
pmake is not typically setuid root, although some Linux distributions default to installing it this way. When a Makefile is executed by pmake, certain user-defined variables can be set in the Makefile by the user. One such variable is the shell definition variable, or .SHELL. By supplying a format string in the check= field of the .SHELL variable, it is possible to write to an arbitrary memory address of the program. This could result in the overwriting of the return address, and execution of arbitrary code with root privileges.
Solution / Fix
Berkeley Parallel Make Shell Definition Format String Vulnerability
Solution:
Vendor updates available:
SuSE Linux 6.4 ppc
SuSE Linux 6.4 alpha
SuSE Linux 6.4
SuSE Linux 7.0 alpha
SuSE Linux 7.0
SuSE Linux 7.0 ppc
SuSE Linux 7.1 x86
SuSE Linux 7.1 alpha
SuSE Linux 7.1 ppc
SuSE Linux 7.2
Solution:
Vendor updates available:
SuSE Linux 6.4 ppc
-
S.u.S.E. 6.4 ppc pmake.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/d2/pmake.rpm
SuSE Linux 6.4 alpha
-
S.u.S.E. 6.4 alpha pmake.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.4/d1/pmake.rpm
SuSE Linux 6.4
-
S.u.S.E. 6.4 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.4/d2/pmake.rpm
SuSE Linux 7.0 alpha
-
S.u.S.E. 7.0 alpha pmake.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/d1/pmake.rpm
SuSE Linux 7.0
-
S.u.S.E. 7.0 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/d2/pmake.rpm
SuSE Linux 7.0 ppc
-
S.u.S.E. 7.0 ppc pmake.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/d2/pmake.rpm
SuSE Linux 7.1 x86
-
S.u.S.E. 7.1 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/d2/pmake.rpm
SuSE Linux 7.1 alpha
-
S.u.S.E. 7.1 alpha pmake.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/d1/pmake.rpm
SuSE Linux 7.1 ppc
-
S.u.S.E. 7.1 ppc pmake.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/d2/pmake.rpm
SuSE Linux 7.2
-
S.u.S.E. 7.2 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/d2/pmake.rpm