xtell Log File Symbolic Link Attack
BID:4197
Info
xtell Log File Symbolic Link Attack
| Bugtraq ID: | 4197 |
| Class: | Race Condition Error |
| CVE: |
CVE-2002-0334 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by "Spybreak" <[email protected]>. |
| Vulnerable: |
xtell xtell 2.6.1 xtell xtell 1.91.1 |
| Not Vulnerable: | |
Discussion
xtell Log File Symbolic Link Attack
xtell is a simple network messaging program. It may be used to transmit terminal messages between users and machines. xtell is available for Linux, BSD and most other Unix based operating systems.
If a file .xtell-log is available in a given user's home directory, and writable by the xtell daemon, certain events will be logged. The xtell process normally runs as the user 'nobody', and the group 'tty'.
A race condition vulnerability has been reported in xtell. It may be possible to create a symbolic link with the file name .xtell-log in a manner that will evade the checks performed by xtell.
Earlier versions of xtell may share some or all of these vulnerabilities. This has not been confirmed.
xtell is a simple network messaging program. It may be used to transmit terminal messages between users and machines. xtell is available for Linux, BSD and most other Unix based operating systems.
If a file .xtell-log is available in a given user's home directory, and writable by the xtell daemon, certain events will be logged. The xtell process normally runs as the user 'nobody', and the group 'tty'.
A race condition vulnerability has been reported in xtell. It may be possible to create a symbolic link with the file name .xtell-log in a manner that will evade the checks performed by xtell.
Earlier versions of xtell may share some or all of these vulnerabilities. This has not been confirmed.
Exploit / POC
xtell Log File Symbolic Link Attack
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
xtell Log File Symbolic Link Attack
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
xtell xtell 1.91.1
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
xtell xtell 1.91.1
-
Debian xtell_1.91.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/xtel l_1.91.1_alpha.deb -
Debian xtell_1.91.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/xtell_ 1.91.1_arm.deb -
Debian xtell_1.91.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xtell _1.91.1_i386.deb -
Debian xtell_1.91.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xtell _1.91.1_m68k.deb -
Debian xtell_1.91.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/xt ell_1.91.1_powerpc.deb -
Debian xtell_1.91.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/xtel l_1.91.1_sparc.deb