libgnomesu PAM Backend 'setuid()' Return Value Local Privilege Escalation Vulnerability
BID:48035
Info
libgnomesu PAM Backend 'setuid()' Return Value Local Privilege Escalation Vulnerability
| Bugtraq ID: | 48035 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1946 |
| Remote: | No |
| Local: | Yes |
| Published: | May 30 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
SuSE Linux 1.0 SuSE Linux 11 SuSE Linux 10.3 SuSE Linux 10.2 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc64 SuSE Linux 10.1 ppc SuSE Linux 10.1 SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc SuSE Linux 10.0 S.u.S.E. openSUSE Factory S.u.S.E. openSUSE 11.4 S.u.S.E. openSUSE 11.3 Hongli Lai libgnomesu 1.0.0 |
| Not Vulnerable: | |
Discussion
libgnomesu PAM Backend 'setuid()' Return Value Local Privilege Escalation Vulnerability
libgnomesu is prone to a local privilege-escalation vulnerability because it fails to properly validate the return value of 'setuid()' function calls in the PAM backend.
Successfully exploiting this issue allows local attackers with access to 'guest', 'cgi', or 'web' user accounts to perform certain actions with superuser privileges, leading to a complete compromise of an affected computer.
libgnomesu is prone to a local privilege-escalation vulnerability because it fails to properly validate the return value of 'setuid()' function calls in the PAM backend.
Successfully exploiting this issue allows local attackers with access to 'guest', 'cgi', or 'web' user accounts to perform certain actions with superuser privileges, leading to a complete compromise of an affected computer.
Exploit / POC
libgnomesu PAM Backend 'setuid()' Return Value Local Privilege Escalation Vulnerability
An attacker uses readily available tools to exploit the issue.
An attacker uses readily available tools to exploit the issue.
References
libgnomesu PAM Backend 'setuid()' Return Value Local Privilege Escalation Vulnerability
References:
References:
- Bug 695627 - VUL-0: libgnomesu pam backend missing setuid() retval check (Sebastian Krahmer)
- CVE request: libgnomesu privilege escalation (Sebastian Krahmer)
- libgnomesu Homepage (Hongli Lai)