Sun SMCBoot Insecure Temporary File Creation Directory Destruction Vulnerability
BID:3763
Info
Sun SMCBoot Insecure Temporary File Creation Directory Destruction Vulnerability
| Bugtraq ID: | 3763 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 28 2001 12:00AM |
| Updated: | Dec 28 2001 12:00AM |
| Credit: | This vulnerability was announced by SecuriTeam on December 28, 2001. |
| Vulnerable: |
Sun SMC 2.0 |
| Not Vulnerable: | |
Discussion
Sun SMCBoot Insecure Temporary File Creation Directory Destruction Vulnerability
The Sun Management Center (SMC) is an integrated system management software package distributed by Sun. It is packaged with recent releases of the Solaris 8 operating system.
The script that starts smcboot does not perform adequate checks prior to attempting to create a directory in /tmp. A directory is created in /tmp to store information for SMC using the smc$PORT name, where port is the TCP port the server listens on; 898 in a default installation. The script does not check for the existence of a previously smc$PORT directory. It is possible to create a symbolic link using the smc$PORT name, and link it to an arbitrary directory. As the smcboot program is run as root, this could result in the overwriting or destruction of files at the end of the symbolic link.
The Sun Management Center (SMC) is an integrated system management software package distributed by Sun. It is packaged with recent releases of the Solaris 8 operating system.
The script that starts smcboot does not perform adequate checks prior to attempting to create a directory in /tmp. A directory is created in /tmp to store information for SMC using the smc$PORT name, where port is the TCP port the server listens on; 898 in a default installation. The script does not check for the existence of a previously smc$PORT directory. It is possible to create a symbolic link using the smc$PORT name, and link it to an arbitrary directory. As the smcboot program is run as root, this could result in the overwriting or destruction of files at the end of the symbolic link.
Exploit / POC
Sun SMCBoot Insecure Temporary File Creation Directory Destruction Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Sun SMCBoot Insecure Temporary File Creation Directory Destruction Vulnerability
Solution:
Patches available:
Sun SMC 2.0
Solution:
Patches available:
Sun SMC 2.0
-
Sun 109134-24
http://sunsolve.sun.com -
Sun 109135-24
http://sunsolve.sun.com
References
Sun SMCBoot Insecure Temporary File Creation Directory Destruction Vulnerability
References:
References:
- Local DoS in Solaris 8 (smcboot) (SecuriTeam)
- Security Patch Downloads (Sun Microsystems)