Platform LSF LSF_ENVDIR Buffer Overflow Vulnerability
BID:3687
Info
Platform LSF LSF_ENVDIR Buffer Overflow Vulnerability
| Bugtraq ID: | 3687 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 2001 12:00AM |
| Updated: | Dec 05 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on December 5th, 2001 by Tomasz Grabowski <[email protected]>. |
| Vulnerable: |
Platform LSF 4.2 Platform LSF 4.0 |
| Not Vulnerable: | |
Discussion
Platform LSF LSF_ENVDIR Buffer Overflow Vulnerability
LSF(Load Sharing Facility) is a series of tools for scheduling, monitoring and analyzing the workload of a network. It supports a number of Unix platforms and can also be used to manage workstations running the Microsoft Windows NT/2000 platforms.
lsadmin and badmin do not implement sufficient bounds checking when they try to determine their environment directory. It is possible to cause a segmentation fault by setting a LSF_ENVDIR environment variable to an excessive length.
As lsadmin and badmin are both setuid root, it is possible for a local attacker to exploit this issue to execute arbitrary code to gain elevated privileges.
LSF(Load Sharing Facility) is a series of tools for scheduling, monitoring and analyzing the workload of a network. It supports a number of Unix platforms and can also be used to manage workstations running the Microsoft Windows NT/2000 platforms.
lsadmin and badmin do not implement sufficient bounds checking when they try to determine their environment directory. It is possible to cause a segmentation fault by setting a LSF_ENVDIR environment variable to an excessive length.
As lsadmin and badmin are both setuid root, it is possible for a local attacker to exploit this issue to execute arbitrary code to gain elevated privileges.
Exploit / POC
Platform LSF LSF_ENVDIR Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Platform LSF LSF_ENVDIR Buffer Overflow Vulnerability
Solution:
Patches are available for LSF 4.2. Users should contact Technical Support <[email protected]> for the exact details about which patches to obtain.
Platform LSF 4.2
Solution:
Patches are available for LSF 4.2. Users should contact Technical Support <[email protected]> for the exact details about which patches to obtain.
Platform LSF 4.2
-
Platform LSF 4.2
ftp.platform.com