FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
BID:36119
Info
FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 36119 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2009 12:00AM |
| Updated: | Aug 25 2009 12:52AM |
| Credit: | Kingcope |
| Vulnerable: |
FreeBSD ftpd 0 FreeBSD FreeBSD 5.0 .x FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 alpha FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 7.0-STABLE FreeBSD FreeBSD 7.0-RELEASE-p8 FreeBSD FreeBSD 7.0-RELEASE-p12 FreeBSD FreeBSD 7.0-RELEASE-p11 FreeBSD FreeBSD 7.0-RELEASE-p11 FreeBSD FreeBSD 7.0-RELEASE FreeBSD FreeBSD 7.0 BETA4 FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 -RELEASE-p9 FreeBSD FreeBSD 7.0 -PRERELEASE FreeBSD FreeBSD 7.0 |
| Not Vulnerable: | |
Discussion
FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
FreeBSD 'ftpd' is prone to a remote privilege-escalation vulnerability.
Successful exploits may allow attackers to break out of chroot jail to gain access to sensitive information or to create denial-of-service conditions. Other attacks may also be possible.
FreeBSD 5.0 and 7.0 are vulnerable; other versions or operating systems may also be affected.
FreeBSD 'ftpd' is prone to a remote privilege-escalation vulnerability.
Successful exploits may allow attackers to break out of chroot jail to gain access to sensitive information or to create denial-of-service conditions. Other attacks may also be possible.
FreeBSD 5.0 and 7.0 are vulnerable; other versions or operating systems may also be affected.
Exploit / POC
FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FreeBSD ftpd 'setusercontext()' Remote Privilege Escalation Vulnerability
References:
References:
- *BSD setusercontext vulnerabilites (Kingcope)
- FreeBSD Homepage (FreeBSD)