LIDS Capability Leakage via LD_PRELOAD Vulnerability
BID:3835
Info
LIDS Capability Leakage via LD_PRELOAD Vulnerability
| Bugtraq ID: | 3835 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 09 2002 12:00AM |
| Updated: | Jan 09 2002 12:00AM |
| Credit: | Discovered by Stealth of Team Teso. |
| Vulnerable: |
LIDS LIDS 1.1 LIDS LIDS 1.0.16 LIDS LIDS 1.0.15 LIDS LIDS 1.0.14 LIDS LIDS 1.0.12 LIDS LIDS 1.0.11 LIDS LIDS 1.0.10 LIDS LIDS 1.0.9 LIDS LIDS 1.0.8 LIDS LIDS 1.0.7 LIDS LIDS 1.0.6 LIDS LIDS 1.0.5 LIDS LIDS 1.0.4 LIDS LIDS 1.0.3 LIDS LIDS 1.0.2 LIDS LIDS 1.0.1 LIDS LIDS 0.11 pre1 LIDS LIDS 0.10 LIDS LIDS 0.9 LIDS LIDS 0.8 LIDS LIDS 0.6 LIDS LIDS 0.4 LIDS LIDS 0.3 LIDS LIDS 0.2 LIDS LIDS 0.1 |
| Not Vulnerable: | |
Discussion
LIDS Capability Leakage via LD_PRELOAD Vulnerability
LIDS ("Linux Intrusion Detection System") is a kernel add-on that implements enhanced filesystem access control and other security features. LIDS also enhances the Linux 'capabilities' security mechanism, which allows for system utilities to perform specific administrative operations without full superuser privileges.
It is possible for attackers to gain capabilities of other programs by executing custom code using the LD_PRELOAD environment variable. LD_PRELOAD is an environment variable that lists shared libraries that are to be loaded in programs at runtime. Attackers can execute code with the capabilities of any program by linking a custom library to the target program via LD_PRELOAD.
This vulnerability allows for security policy to be violated. Attackers who have obtained root access may gain the capabilities assigned to any program. In addition, local users may be able to elevate privileges by exploiting non-setuid programs assigned the CAP_SETUID capability.
LIDS ("Linux Intrusion Detection System") is a kernel add-on that implements enhanced filesystem access control and other security features. LIDS also enhances the Linux 'capabilities' security mechanism, which allows for system utilities to perform specific administrative operations without full superuser privileges.
It is possible for attackers to gain capabilities of other programs by executing custom code using the LD_PRELOAD environment variable. LD_PRELOAD is an environment variable that lists shared libraries that are to be loaded in programs at runtime. Attackers can execute code with the capabilities of any program by linking a custom library to the target program via LD_PRELOAD.
This vulnerability allows for security policy to be violated. Attackers who have obtained root access may gain the capabilities assigned to any program. In addition, local users may be able to elevate privileges by exploiting non-setuid programs assigned the CAP_SETUID capability.
Exploit / POC
LIDS Capability Leakage via LD_PRELOAD Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
LIDS Capability Leakage via LD_PRELOAD Vulnerability
Solution:
Patches are available:
LIDS LIDS 0.1
LIDS LIDS 0.10
LIDS LIDS 0.11 pre1
LIDS LIDS 0.2
LIDS LIDS 0.3
LIDS LIDS 0.4
LIDS LIDS 0.6
LIDS LIDS 0.8
LIDS LIDS 0.9
LIDS LIDS 1.0.1
LIDS LIDS 1.0.10
LIDS LIDS 1.0.11
LIDS LIDS 1.0.12
LIDS LIDS 1.0.14
LIDS LIDS 1.0.15
LIDS LIDS 1.0.16
LIDS LIDS 1.0.2
LIDS LIDS 1.0.3
LIDS LIDS 1.0.4
LIDS LIDS 1.0.5
LIDS LIDS 1.0.6
LIDS LIDS 1.0.7
LIDS LIDS 1.0.8
LIDS LIDS 1.0.9
LIDS LIDS 1.1
Solution:
Patches are available:
LIDS LIDS 0.1
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.10
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.11 pre1
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.2
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.3
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.4
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.6
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.8
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 0.9
-
LIDS LIDS-security-patch-0.10.1-2.2.20.diff.gz
Users must apply this to version 0.10.1. For those not running LIDS 0.10.1, the version should be upgraded before this patch can be applied.
http://www.lids.org/download/LIDS-security-patch-0.10.1-2.2.20.diff.gz
LIDS LIDS 1.0.1
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.10
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.11
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.12
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.14
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.15
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.16
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.2
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.3
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.4
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.5
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.6
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.7
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.8
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.0.9
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz
LIDS LIDS 1.1
-
LIDS lids-1.1.1pre2-2.4.16.tar.gz
http://www.lids.org/download/lids-1.1.1pre2-2.4.16.tar.gz