Platform LSF Logging Facilities Symbolic Link Vulnerability
BID:3690
Info
Platform LSF Logging Facilities Symbolic Link Vulnerability
| Bugtraq ID: | 3690 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 13 2001 12:00AM |
| Updated: | Dec 13 2001 12:00AM |
| Credit: | This vulnerability was discovered by Tomasz Grabowski <[email protected]>, and announced via the Bugtraq mailing list on December 5, 2001. |
| Vulnerable: |
Platform LSF 4.2 Platform LSF 4.0 |
| Not Vulnerable: | |
Discussion
Platform LSF Logging Facilities Symbolic Link Vulnerability
LSF(Load Sharing Facility) is a series of tools for scheduling, monitoring and analyzing the workload of a network. It supports a number of Unix platforms and can also be used to manage workstations running the Microsoft Windows NT/2000 platforms.
Upon execution, the software does not check for pre-existing log files. Since the program runs with root privileges, it is possible for a local user to create symbolic links to arbitrary files. The log files are created with world-readable permissions, thus allowing the attacker to gain read access to the file at the end of the symbolic link. This could allow a local attacker to gain administrative access on a vulnerable system.
LSF(Load Sharing Facility) is a series of tools for scheduling, monitoring and analyzing the workload of a network. It supports a number of Unix platforms and can also be used to manage workstations running the Microsoft Windows NT/2000 platforms.
Upon execution, the software does not check for pre-existing log files. Since the program runs with root privileges, it is possible for a local user to create symbolic links to arbitrary files. The log files are created with world-readable permissions, thus allowing the attacker to gain read access to the file at the end of the symbolic link. This could allow a local attacker to gain administrative access on a vulnerable system.
Exploit / POC
Platform LSF Logging Facilities Symbolic Link Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Platform LSF Logging Facilities Symbolic Link Vulnerability
Solution:
The vendor has released a patch addressing this issue:
Platform LSF 4.2
Solution:
The vendor has released a patch addressing this issue:
Platform LSF 4.2
-
Platform LSF 4.2
ftp.platform.com
References
Platform LSF Logging Facilities Symbolic Link Vulnerability
References:
References: