HP-UX RLPDaemon Arbitrary Log File Creation Vulnerability
BID:3701
Info
HP-UX RLPDaemon Arbitrary Log File Creation Vulnerability
| Bugtraq ID: | 3701 |
| Class: | Design Error |
| CVE: |
CVE-2001-1198 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 15 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Vulnerability discovery credited to G.Borglum <[email protected]. |
| Vulnerable: |
HP HP-UX 11.0 HP HP-UX 10.20 |
| Not Vulnerable: | |
Discussion
HP-UX RLPDaemon Arbitrary Log File Creation Vulnerability
HP-UX is the Unix Operating System developed and distributed by Hewlett Packard.
A problem has been discovered that could allow a local user to gain elevated privileges. The problem manifests itself when the program is invoked with all three supported flags (-i, -l, and -L). The rlpdaemon program is setuid root. When executed with all three flags, the program can be used to create a file in any place on the file system. With carefully crafted requests, a local user could generate a log file in a specific place with any file name, and could allow the user to gain elevated privileges.
HP-UX is the Unix Operating System developed and distributed by Hewlett Packard.
A problem has been discovered that could allow a local user to gain elevated privileges. The problem manifests itself when the program is invoked with all three supported flags (-i, -l, and -L). The rlpdaemon program is setuid root. When executed with all three flags, the program can be used to create a file in any place on the file system. With carefully crafted requests, a local user could generate a log file in a specific place with any file name, and could allow the user to gain elevated privileges.
Exploit / POC
HP-UX RLPDaemon Arbitrary Log File Creation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP-UX RLPDaemon Arbitrary Log File Creation Vulnerability
Solution:
Vendor fixes available:
HP HP-UX 10.20
HP HP-UX 11.0
Solution:
Vendor fixes available:
HP HP-UX 10.20
-
HP PHCO_25109
http://itrc.hp.com/
HP HP-UX 11.0
-
HP PHCO_25110
http://itrc.hp.com/ -
HP PHCO_27132
http://itrc.hp.com
References
HP-UX RLPDaemon Arbitrary Log File Creation Vulnerability
References:
References: