Berkeley Parallel Make Buffer Overflow Vulnerability
BID:3573
Info
Berkeley Parallel Make Buffer Overflow Vulnerability
| Bugtraq ID: | 3573 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 21 2001 12:00AM |
| Updated: | Nov 21 2001 12:00AM |
| Credit: | This vulnerability was first announced to Bugtraq by Paul Starzetz <[email protected]> on November 21, 2001. |
| Vulnerable: |
SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.0 ppc SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 alpha SuSE Linux 6.4 |
| Not Vulnerable: |
Slackware Linux 8.0 Slackware Linux 7.1 Redhat Linux 7.2 i386 Redhat Linux 7.2 alpha |
Discussion
Berkeley Parallel Make Buffer Overflow Vulnerability
Parallel Make (pmake) is a freely available version of the make program, originally distributed with Berkeley Unix. It is designed to execute Makefiles and build programs.
pmake is not typically setuid root, although some Linux distributions default to installing it this way. When a Makefile is executed by pmake, certain user-defined variables can be set in the Makefile by the user. One such variable is the shell definition variable, or .SHELL. By supplying a string of greater than 512 characters in the check= field of the .SHELL variable, it is possible to overwrite the return address, and execute of arbitrary code with root privileges.
Parallel Make (pmake) is a freely available version of the make program, originally distributed with Berkeley Unix. It is designed to execute Makefiles and build programs.
pmake is not typically setuid root, although some Linux distributions default to installing it this way. When a Makefile is executed by pmake, certain user-defined variables can be set in the Makefile by the user. One such variable is the shell definition variable, or .SHELL. By supplying a string of greater than 512 characters in the check= field of the .SHELL variable, it is possible to overwrite the return address, and execute of arbitrary code with root privileges.
Exploit / POC
Berkeley Parallel Make Buffer Overflow Vulnerability
Contributed by Paul Starzetz <[email protected]>:
Contributed by Paul Starzetz <[email protected]>:
Solution / Fix
Berkeley Parallel Make Buffer Overflow Vulnerability
Solution:
Vendor updates available:
SuSE Linux 6.4 ppc
SuSE Linux 6.4 alpha
SuSE Linux 6.4
SuSE Linux 7.0 alpha
SuSE Linux 7.0
SuSE Linux 7.0 ppc
SuSE Linux 7.1 x86
SuSE Linux 7.1 alpha
SuSE Linux 7.1 ppc
SuSE Linux 7.2
Solution:
Vendor updates available:
SuSE Linux 6.4 ppc
-
S.u.S.E. 6.4 ppc pmake.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/d2/pmake.rpm
SuSE Linux 6.4 alpha
-
S.u.S.E. 6.4 alpha pmake.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.4/d1/pmake.rpm
SuSE Linux 6.4
-
S.u.S.E. 6.4 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.4/d2/pmake.rpm
SuSE Linux 7.0 alpha
-
S.u.S.E. 7.0 alpha pmake.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/d1/pmake.rpm
SuSE Linux 7.0
-
S.u.S.E. 7.0 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/d2/pmake.rpm
SuSE Linux 7.0 ppc
-
S.u.S.E. 7.0 ppc pmake.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/d2/pmake.rpm
SuSE Linux 7.1 x86
-
S.u.S.E. 7.1 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/d2/pmake.rpm
SuSE Linux 7.1 alpha
-
S.u.S.E. 7.1 alpha pmake.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/d1/pmake.rpm
SuSE Linux 7.1 ppc
-
S.u.S.E. 7.1 ppc pmake.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/d2/pmake.rpm
SuSE Linux 7.2
-
S.u.S.E. 7.2 i386 pmake.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/d2/pmake.rpm
References
Berkeley Parallel Make Buffer Overflow Vulnerability
References:
References: