FreeBSD Package Add Insecure Temporary Directory Creation Vulnerability
BID:3819
Info
FreeBSD Package Add Insecure Temporary Directory Creation Vulnerability
| Bugtraq ID: | 3819 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 04 2002 12:00AM |
| Updated: | Jan 04 2002 12:00AM |
| Credit: | This vulnerability was discovered by The Anarcat <[email protected]>, and announced in a FreeBSD Security Advisory on January 4, 2002. |
| Vulnerable: |
FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 |
| Not Vulnerable: | |
Discussion
FreeBSD Package Add Insecure Temporary Directory Creation Vulnerability
FreeBSD is a freely available, open source clone of the Unix Operating System. It is maintained by the FreeBSD project.
When pkg_add is executed, the directory the contents of the package are extracted to is created with permissions of 755. With this permission set, it is possible for a local user to descend the directory tree. In the event that any subdirectories have been created with world-writable permissions, the user could either remove the data in those directories, or trojan the files to later gain elevated privileges.
FreeBSD is a freely available, open source clone of the Unix Operating System. It is maintained by the FreeBSD project.
When pkg_add is executed, the directory the contents of the package are extracted to is created with permissions of 755. With this permission set, it is possible for a local user to descend the directory tree. In the event that any subdirectories have been created with world-writable permissions, the user could either remove the data in those directories, or trojan the files to later gain elevated privileges.
Exploit / POC
FreeBSD Package Add Insecure Temporary Directory Creation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
FreeBSD Package Add Insecure Temporary Directory Creation Vulnerability
Solution:
Fixes available:
FreeBSD FreeBSD 4.2
FreeBSD FreeBSD 4.3
FreeBSD FreeBSD 4.4
Solution:
Fixes available:
FreeBSD FreeBSD 4.2
-
FreeBSD pkg_add.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:01/pkg_add.patch
FreeBSD FreeBSD 4.3
-
FreeBSD pkg_add.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:01/pkg_add.patch
FreeBSD FreeBSD 4.4
-
FreeBSD pkg_add.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:01/pkg_add.patch
References
FreeBSD Package Add Insecure Temporary Directory Creation Vulnerability
References:
References: