GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
BID:4742
Info
GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
| Bugtraq ID: | 4742 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 14 2002 12:00AM |
| Updated: | May 14 2002 12:00AM |
| Credit: | This vulnerability discovery credited to AERAsec. |
| Vulnerable: |
SCO Open Server 5.0.7 SCO Open Server 5.0.6 Redhat sharutils-4.2.1-8.7.x.i386.rpm GNU sharutils 4.2 Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.0 a PK3 (BL17) Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 f PK7 (BL18) Caldera OpenLinux Workstation 3.1.1 Caldera OpenLinux Workstation 3.1 Caldera OpenLinux Server 3.1.1 Caldera OpenLinux Server 3.1 Avaya Intuity R5 R5.1.46 |
| Not Vulnerable: |
GNU sharutils 4.2.1 |
Discussion
GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
Sharutils is a freely available, open source suite of tools maintained by the GNU. It is designed for use on Unix and Linux operating systems.
Prior to decoding a uuencoded file, uudecode does not check for the existence of the file to be created from the decoded archive. As a result, a decoded file may overwrite another file in the temporary directory, provided the user of uudecode has write permission to the file.
Sharutils is a freely available, open source suite of tools maintained by the GNU. It is designed for use on Unix and Linux operating systems.
Prior to decoding a uuencoded file, uudecode does not check for the existence of the file to be created from the decoded archive. As a result, a decoded file may overwrite another file in the temporary directory, provided the user of uudecode has write permission to the file.
Exploit / POC
GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
Solution:
Hewlett-Packard Company recommends that customers who have installed sharutils download the RPMs listed in the following Red Hat Security Advisory:
2002-05-14 RHSA-2002:065 Updated sharutils package fixes uudecode issue.
SCO has released a security update. OpenLinux, OpenUnix, and UnixWare fixes are available.
Gentoo Linux has released a security advisory. It is recommended that all Gentoo Linux users who are running sys-apps/sharutils-4.2.1-r5 and earlier update their systems as follows:
emerge rsync
emerge sharutils
emerge clean
Red Hat has released an advisory (RHSA-2003:180-05). Fixes are available for Red Hat Enterprise Linux AS (v. 2.1) and can be obtained from the Red Hat Network http://rhn.redhat.com/.
SCO has released advisory SCOSA-2004.12 and fixes addressing this issue for OpenServer 5.0.6 and 5.0.7. Please see the referenced advisory for further information.
Avaya has announced that Intuity R5.1.46 is affected and that fixes are pending. Please see the following advisory for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=198481&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Fixes available:
Caldera OpenLinux Server 3.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1.1
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 f PK7 (BL18)
GNU sharutils 4.2
Compaq Tru64 5.0 a PK3 (BL17)
Compaq Tru64 5.1 PK5 (BL19)
Compaq Tru64 5.1 a PK3 (BL3)
Solution:
Hewlett-Packard Company recommends that customers who have installed sharutils download the RPMs listed in the following Red Hat Security Advisory:
2002-05-14 RHSA-2002:065 Updated sharutils package fixes uudecode issue.
SCO has released a security update. OpenLinux, OpenUnix, and UnixWare fixes are available.
Gentoo Linux has released a security advisory. It is recommended that all Gentoo Linux users who are running sys-apps/sharutils-4.2.1-r5 and earlier update their systems as follows:
emerge rsync
emerge sharutils
emerge clean
Red Hat has released an advisory (RHSA-2003:180-05). Fixes are available for Red Hat Enterprise Linux AS (v. 2.1) and can be obtained from the Red Hat Network http://rhn.redhat.com/.
SCO has released advisory SCOSA-2004.12 and fixes addressing this issue for OpenServer 5.0.6 and 5.0.7. Please see the referenced advisory for further information.
Avaya has announced that Intuity R5.1.46 is affected and that fixes are pending. Please see the following advisory for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=198481&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Fixes available:
Caldera OpenLinux Server 3.1
-
SCO sharutils-4.2.1-7MR.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-040.0/RPM S -
SCO sharutils-4.2.1-7MR.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-040.0/SRP MS
Caldera OpenLinux Workstation 3.1
-
SCO sharutils-4.2.1-7MR.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-040. 0/RPMS -
SCO sharutils-4.2.1-7MR.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-040. 0/SRPMS
Caldera OpenLinux Server 3.1.1
-
SCO sharutils-4.2.1-7MR.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-040.0/R PMS -
SCO sharutils-4.2.1-7MR.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-040.0/S RPMS
Caldera OpenLinux Workstation 3.1.1
-
SCO sharutils-4.2.1-7MR.1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-04 0.0/RPMS -
SCO sharutils-4.2.1-7MR.1.src.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-04 0.0/SRPMS
Compaq Tru64 4.0 g PK3 (BL17)
-
HP t64v40gb17-c0020202-16068-es-20021114.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0g/t64v40gb17-c00 20202-16068-es-20021114.tar
Compaq Tru64 4.0 f PK7 (BL18)
-
HP duv40fb18-c0082402-16085-es-20021115.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0f/duv40fb18-c008 2402-16085-es-20021115.tar
GNU sharutils 4.2
-
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
Corporate Server 1.0.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
snf 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
x86 7.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
x86 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
x86 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
x86 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.i586.rpm
x86 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.ia64.rpm
ia64 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.ppc.rpm
ppc 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sharutils-4.2.1-8.1mdk.ppc.rpm
ppc 8.2
http://www.mandrakesecure.net/en/ftp.php -
Red Hat sharutils-4.2.1-2.6.x.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/sharutils-4.2.1-2.6.x.alpha.r pm -
Red Hat sharutils-4.2.1-2.6.x.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/sharutils-4.2.1-2.6.x.i386.rpm -
Red Hat sharutils-4.2.1-2.6.x.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/sharutils-4.2.1-2.6.x.sparc.r pm -
Red Hat sharutils-4.2.1-8.7.x.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/sharutils-4.2.1-8.7.x.alpha.r pm -
Red Hat sharutils-4.2.1-8.7.x.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/sharutils-4.2.1-8.7.x.alpha.r pm -
Red Hat sharutils-4.2.1-8.7.x.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/sharutils-4.2.1-8.7.x.i386.rpm -
Red Hat sharutils-4.2.1-8.7.x.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/sharutils-4.2.1-8.7.x.i386.rpm -
Red Hat sharutils-4.2.1-8.7.x.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/sharutils-4.2.1-8.7.x.ia64.rpm -
Red Hat sharutils-4.2.1-8.7.x.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/i386/sharutils-4.2.1-8.7.x.i386.rpm -
Red Hat sharutils-4.2.1-8.7.x.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/sharutils-4.2.1-8.7.x.ia64.rpm -
SCO erg712093.pkg.Z
ftp://ftp.sco.com/pub/updates/OpenUNIX/CSSA-2002-SCO.44
Compaq Tru64 5.0 a PK3 (BL17)
-
HP t64v50ab17-c0023802-16066-es-20021114.tar
http://ftp.support.compaq.com/patches/public/unix/v5.0a/t64v50ab17-c00 23802-16066-es-20021114.tar
Compaq Tru64 5.1 PK5 (BL19)
-
HP t64v51b19-c0142502-16065-es-20021114.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1/t64v51b19-c0142 502-16065-es-20021114.tar
Compaq Tru64 5.1 a PK3 (BL3)
-
HP t64v51ab3-c0055902-16064-es-20021114.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1a/t64v51ab3-c005 5902-16064-es-20021114.tar
References
GNU SharUtils UUDecode Symbolic Link Attack Vulnerability
References:
References:
- Insecure outputfile handling in uudecode (AERAsec)
- RHSA-2003:180-05 (Red Hat)
- TITLE: SSRT2301 - HP Tru64 UNIX uudecode Potential Security Vulnerability (HP)
- TITLE: SSRT2301 - HP Tru64 UNIX uudecode Potential Security Vulnerability (HP)
- TITLE: SSRT2301 - HP Tru64 UNIX uudecode Potential Security Vulnerability (HP)
- TITLE: SSRT2301 - HP Tru64 UNIX uudecode Potential Security Vulnerability (HP)
- TITLE: SSRT2301 - HP Tru64 UNIX uudecode Potential Security Vulnerability (HP)