LogWatch Insecure Temporary Directory Creation Vulnerability
BID:4374
Info
LogWatch Insecure Temporary Directory Creation Vulnerability
| Bugtraq ID: | 4374 |
| Class: | Race Condition Error |
| CVE: |
CVE-2002-0162 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 27 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | This vulnerability discovery credited to Spybreak <[email protected]>. |
| Vulnerable: |
LogWatch LogWatch 2.5 LogWatch LogWatch 2.1.1 |
| Not Vulnerable: |
LogWatch LogWatch 2.6 |
Discussion
LogWatch Insecure Temporary Directory Creation Vulnerability
LogWatch is a freely available, open source script for monitoring log files. It may be used with the Linux and Unix Operating systems.
Upon execution, LogWatch creates a directory in /tmp. This directory uses the name logwatch.$pid, where $pid is the process id of the executing script. The LogWatch script does not check for an already existing directory or contents of the already existing directory. It is therefore possible for a local user to create a malicious logwatch.$pid directory using predicted process IDs, and place malicious files in the directory which will be executed.
LogWatch is a freely available, open source script for monitoring log files. It may be used with the Linux and Unix Operating systems.
Upon execution, LogWatch creates a directory in /tmp. This directory uses the name logwatch.$pid, where $pid is the process id of the executing script. The LogWatch script does not check for an already existing directory or contents of the already existing directory. It is therefore possible for a local user to create a malicious logwatch.$pid directory using predicted process IDs, and place malicious files in the directory which will be executed.
Exploit / POC
LogWatch Insecure Temporary Directory Creation Vulnerability
Exploit contributed by Spybreak <[email protected]>.
Exploit contributed by Spybreak <[email protected]>.
Solution / Fix
LogWatch Insecure Temporary Directory Creation Vulnerability
Solution:
Fixes available:
LogWatch LogWatch 2.1.1
Solution:
Fixes available:
LogWatch LogWatch 2.1.1
-
Red Hat logwatch-2.6-1.noarch.rpm
ftp://updates.redhat.com/6.2/en/powertools/noarch/logwatch-2.6-1.noarc h.rpm -
Red Hat logwatch-2.6-1.noarch.rpm
ftp://updates.redhat.com/7.0/en/powertools/noarch/logwatch-2.6-1.noarc h.rpm -
Red Hat logwatch-2.6-1.noarch.rpm
ftp://updates.redhat.com/7.1/en/powertools/noarch/logwatch-2.6-1.noarc h.rpm -
Red Hat logwatch-2.6-1.noarch.rpm
ftp://updates.redhat.com/7.2/en/os/noarch/logwatch-2.6-1.noarch.rpm
References
LogWatch Insecure Temporary Directory Creation Vulnerability
References:
References: