CHUID Privileged File Owner Changing Vulnerability
BID:3938
Info
CHUID Privileged File Owner Changing Vulnerability
| Bugtraq ID: | 3938 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0145 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was announced by Scott Parish <[email protected]> via Bugtraq on January 21, 2002. |
| Vulnerable: |
chuid chuid 1.2 chuid chuid 1.1 chuid chuid 1.0 |
| Not Vulnerable: |
chuid chuid 1.3 |
Discussion
CHUID Privileged File Owner Changing Vulnerability
chuid is a freely available, open source user id changing utility. It was written and is maintained by Scott Parish. It is designed for use on the Linux operating system.
chuid does not properly handle user-supplied input. Due to insufficient checking of user input, it is possible for a remote user to change the ownership of a file owned by a privileged user. This could allow a remote user to change the ownership or group membership of a restricted or privileged file.
chuid is a freely available, open source user id changing utility. It was written and is maintained by Scott Parish. It is designed for use on the Linux operating system.
chuid does not properly handle user-supplied input. Due to insufficient checking of user input, it is possible for a remote user to change the ownership of a file owned by a privileged user. This could allow a remote user to change the ownership or group membership of a restricted or privileged file.