SuSE Shadow File Truncation Vulnerability
BID:4757
Info
SuSE Shadow File Truncation Vulnerability
| Bugtraq ID: | 4757 |
| Class: | Environment Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 16 2002 12:00AM |
| Updated: | May 16 2002 12:00AM |
| Credit: | Discovery of this issue is credited to the SuSE Security Team. |
| Vulnerable: |
SuSE Linux 8.0 |
| Not Vulnerable: | |
Discussion
SuSE Shadow File Truncation Vulnerability
A vulnerability has been discovered in the shadow package that ships with the SuSE Linux distribution. It has been reported that a local attacker may be able to cause data in /etc/passwd and /etc/shadow to be truncated or possibly even appended to with attacker-supplied data. This can occur of the attacker sets filesize limitations prior to invoking the utilities that operate on these files. At the very least, local users can corrupt vital files. This would possibly result in a denial of service. Under some circumstances successful exploitation of this vulnerability may enable a local attacker to elevate privileges, possibly even gaining root privileges. SuSE has stated that it is not possible for local attackers to obtain root privileges with the default configuration of SuSE Linux.
A vulnerability has been discovered in the shadow package that ships with the SuSE Linux distribution. It has been reported that a local attacker may be able to cause data in /etc/passwd and /etc/shadow to be truncated or possibly even appended to with attacker-supplied data. This can occur of the attacker sets filesize limitations prior to invoking the utilities that operate on these files. At the very least, local users can corrupt vital files. This would possibly result in a denial of service. Under some circumstances successful exploitation of this vulnerability may enable a local attacker to elevate privileges, possibly even gaining root privileges. SuSE has stated that it is not possible for local attackers to obtain root privileges with the default configuration of SuSE Linux.
Exploit / POC
SuSE Shadow File Truncation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SuSE Shadow File Truncation Vulnerability
Solution:
The vendor has made upgrades available.
SuSE Linux 8.0
Solution:
The vendor has made upgrades available.
SuSE Linux 8.0
-
SuSE pam-modules-2002.3.9-31.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/a1/pam-modules-2002.3.9-31 .i386.rpm -
SuSE pam-modules-2002.3.9-31.src.rpm
Source RPM.
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/pam-modules-2002.3.9-3 1.src.rpm -
SuSE shadow-4.0.2-88.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/a1/shadow-4.0.2-88.i386.rp m -
SuSE shadow-4.0.2-88.src.rpm
Source RPM.
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/shadow-4.0.2-88.src.rp m
References
SuSE Shadow File Truncation Vulnerability
References:
References: