BMC Patrol Symbolic Link Vulnerability
BID:534
Info
BMC Patrol Symbolic Link Vulnerability
| Bugtraq ID: | 534 |
| Class: | Origin Validation Error |
| CVE: |
CVE-1999-1459 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 02 1998 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | First released in an ISS X-Force Advisory published on November 2, 1998. |
| Vulnerable: |
Bmc Patrol 3.2.3 Bmc Patrol 3.2 |
| Not Vulnerable: | |
Discussion
BMC Patrol Symbolic Link Vulnerability
In an advisory released by ISS on November 02, 1998, it was made aware that BMC's product, Patrol, was vulnerable to a possible root compromise. The vulnerability has to do with temporary files created by the world-executable Patrol Agent. Attackers can create symlinks in /tmp that Patrol Agent will follow (along with the root priviliges that, by default, Patrol Agent posesses). It may be possible to write arbitrary data to the target files to obtain root access.
In an advisory released by ISS on November 02, 1998, it was made aware that BMC's product, Patrol, was vulnerable to a possible root compromise. The vulnerability has to do with temporary files created by the world-executable Patrol Agent. Attackers can create symlinks in /tmp that Patrol Agent will follow (along with the root priviliges that, by default, Patrol Agent posesses). It may be possible to write arbitrary data to the target files to obtain root access.
References
BMC Patrol Symbolic Link Vulnerability
References:
References: