GNU SharUtils UUDecode Symbolic Link Attack Vulnerability

BID:4742

Info

GNU SharUtils UUDecode Symbolic Link Attack Vulnerability

Bugtraq ID: 4742
Class: Design Error
CVE:
Remote: No
Local: Yes
Published: May 14 2002 12:00AM
Updated: May 14 2002 12:00AM
Credit: This vulnerability discovery credited to AERAsec.
Vulnerable: SCO Open Server 5.0.7
SCO Open Server 5.0.6
Redhat sharutils-4.2.1-8.7.x.i386.rpm
+ Redhat Enterprise Linux AS 2.1
GNU sharutils 4.2
+ Caldera OpenUnix 8.0
+ Caldera UnixWare 7.1.1
+ HP Secure OS software for Linux 1.0
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 PK5 (BL19)
Compaq Tru64 5.0 a PK3 (BL17)
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 f PK7 (BL18)
Caldera OpenLinux Workstation 3.1.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Server 3.1
Avaya Intuity R5 R5.1.46
Not Vulnerable: GNU sharutils 4.2.1
+ Gentoo Linux 1.4 _rc3
+ Gentoo Linux 1.4 _rc2
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.4
+ HP Secure OS software for Linux 1.0
+ MandrakeSoft Corporate Server 3.0 x86_64
+ MandrakeSoft Corporate Server 3.0
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
+ Redhat Fedora Core3
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Turbolinux Appliance Server 1.0 Workgroup Edition
+ Turbolinux Appliance Server 1.0 Hosting Edition
+ Turbolinux Appliance Server Hosting Edition 1.0
+ Turbolinux Appliance Server Workgroup Edition 1.0
+ Turbolinux Home
+ Turbolinux Turbolinux 10 F...
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Workstation 8.0
+ Turbolinux Turbolinux Workstation 7.0
+ Ubuntu Ubuntu Linux 4.1 ppc
+ Ubuntu Ubuntu Linux 4.1 ia64
+ Ubuntu Ubuntu Linux 4.1 ia32

Discussion

GNU SharUtils UUDecode Symbolic Link Attack Vulnerability

Sharutils is a freely available, open source suite of tools maintained by the GNU. It is designed for use on Unix and Linux operating systems.

Prior to decoding a uuencoded file, uudecode does not check for the existence of the file to be created from the decoded archive. As a result, a decoded file may overwrite another file in the temporary directory, provided the user of uudecode has write permission to the file.

Exploit / POC

GNU SharUtils UUDecode Symbolic Link Attack Vulnerability

No exploit is required for this vulnerability.

Solution / Fix

GNU SharUtils UUDecode Symbolic Link Attack Vulnerability

Solution:
Hewlett-Packard Company recommends that customers who have installed sharutils download the RPMs listed in the following Red Hat Security Advisory:

2002-05-14 RHSA-2002:065 Updated sharutils package fixes uudecode issue.

SCO has released a security update. OpenLinux, OpenUnix, and UnixWare fixes are available.

Gentoo Linux has released a security advisory. It is recommended that all Gentoo Linux users who are running sys-apps/sharutils-4.2.1-r5 and earlier update their systems as follows:

emerge rsync
emerge sharutils
emerge clean

Red Hat has released an advisory (RHSA-2003:180-05). Fixes are available for Red Hat Enterprise Linux AS (v. 2.1) and can be obtained from the Red Hat Network http://rhn.redhat.com/.

SCO has released advisory SCOSA-2004.12 and fixes addressing this issue for OpenServer 5.0.6 and 5.0.7. Please see the referenced advisory for further information.

Avaya has announced that Intuity R5.1.46 is affected and that fixes are pending. Please see the following advisory for further details:

http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=198481&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()

Fixes available:


Caldera OpenLinux Server 3.1

Caldera OpenLinux Workstation 3.1

Caldera OpenLinux Server 3.1.1

Caldera OpenLinux Workstation 3.1.1

Compaq Tru64 4.0 g PK3 (BL17)

Compaq Tru64 4.0 f PK7 (BL18)

GNU sharutils 4.2

Compaq Tru64 5.0 a PK3 (BL17)

Compaq Tru64 5.1 PK5 (BL19)

Compaq Tru64 5.1 a PK3 (BL3)

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report