UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
BID:3818
Info
UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
| Bugtraq ID: | 3818 |
| Class: | Configuration Error |
| CVE: |
CVE-2002-0105 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 08 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This issue was submitted to BugTraq on January 8th, 2002 by jG gM <[email protected]>. |
| Vulnerable: |
Caldera UnixWare 7.1 .0 |
| Not Vulnerable: | |
Discussion
UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
dtlogin is a utility that allows users to log into a CDE session
either locally or remotely. dtlogin logs errors to /var/dt/Xerrors.
UnixWare 7.1 installs the CDE error log directory (/var/dt/) and its contents with 777 privileges. This makes it prone to symbolic link attacks, which may under some circumstances cause other files to be overwritten with attacker-supplied data.
This also has a potential to cause a denial of service or a loss of critical data. There also exists a possibility that a local attacker may gain elevated privileges as a result of this issue.
This issue has been confirmed for Unixware 7.1, it is not known whether other versions or distributions are affected by this issue.
dtlogin is a utility that allows users to log into a CDE session
either locally or remotely. dtlogin logs errors to /var/dt/Xerrors.
UnixWare 7.1 installs the CDE error log directory (/var/dt/) and its contents with 777 privileges. This makes it prone to symbolic link attacks, which may under some circumstances cause other files to be overwritten with attacker-supplied data.
This also has a potential to cause a denial of service or a loss of critical data. There also exists a possibility that a local attacker may gain elevated privileges as a result of this issue.
This issue has been confirmed for Unixware 7.1, it is not known whether other versions or distributions are affected by this issue.
Exploit / POC
UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
References:
References: