FreeBSD k5su Wheel Group Membership Validation Vulnerability
BID:4777
Info
FreeBSD k5su Wheel Group Membership Validation Vulnerability
| Bugtraq ID: | 4777 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 20 2002 12:00AM |
| Updated: | May 20 2002 12:00AM |
| Credit: | This issue was reported in a FreeBSD Security Advisory. |
| Vulnerable: |
FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 |
| Not Vulnerable: | |
Discussion
FreeBSD k5su Wheel Group Membership Validation Vulnerability
k5su is a utility for the FreeBSD operating system which is similar to su.
To be used, the su utility normally requires that the local user is a member of the 'wheel' group. k5su does not sufficiently validate that the user possesses this group membership and may be used by arbitrary users who know the superuser password.
It should be noted that administrators must explicitly install k5su and this vulnerability is not present in default installations of the FreeBSD operating system.
k5su is a utility for the FreeBSD operating system which is similar to su.
To be used, the su utility normally requires that the local user is a member of the 'wheel' group. k5su does not sufficiently validate that the user possesses this group membership and may be used by arbitrary users who know the superuser password.
It should be noted that administrators must explicitly install k5su and this vulnerability is not present in default installations of the FreeBSD operating system.
Exploit / POC
FreeBSD k5su Wheel Group Membership Validation Vulnerability
Users must be authenticated locally and also possess authentication credentials for the superuser to take advantage of this issue.
Users must be authenticated locally and also possess authentication credentials for the superuser to take advantage of this issue.
Solution / Fix
FreeBSD k5su Wheel Group Membership Validation Vulnerability
Solution:
k5su is installed with the krb5 distribution and the utility is now disabled by default in the current version of FreeBSD-STABLE.
Solution:
k5su is installed with the krb5 distribution and the utility is now disabled by default in the current version of FreeBSD-STABLE.
References
FreeBSD k5su Wheel Group Membership Validation Vulnerability
References:
References: