SAS SASTCPD Local Root Code Execution Vulnerability
BID:3994
Info
SAS SASTCPD Local Root Code Execution Vulnerability
| Bugtraq ID: | 3994 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 30 2002 12:00AM |
| Updated: | Jan 30 2002 12:00AM |
| Credit: | Posted to the Bugtraq mailing list by rpc <[email protected]>. |
| Vulnerable: |
SAS Integration Technologies 8.0 SAS Base 8.0 |
| Not Vulnerable: | |
Discussion
SAS SASTCPD Local Root Code Execution Vulnerability
sastcpd is a "Job Spawner" included with the base installation of the SAS Software infrastructure. It is available for various platforms, including Unix, Linux, and Microsoft operating systems.
sastcpd passes environment variables directly to an execve call. As sastcpd is installed suid root by default, this can lead to the execution of arbitrary programs as the root user. Exploitation of this vulnerability will lead directly to local compromise of the root user.
sastcpd is a "Job Spawner" included with the base installation of the SAS Software infrastructure. It is available for various platforms, including Unix, Linux, and Microsoft operating systems.
sastcpd passes environment variables directly to an execve call. As sastcpd is installed suid root by default, this can lead to the execution of arbitrary programs as the root user. Exploitation of this vulnerability will lead directly to local compromise of the root user.
Exploit / POC
SAS SASTCPD Local Root Code Execution Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
SAS SASTCPD Local Root Code Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SAS SASTCPD Local Root Code Execution Vulnerability
References:
References: