Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
BID:5355
Info
Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
| Bugtraq ID: | 5355 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 2002 12:00AM |
| Updated: | Jul 29 2002 12:00AM |
| Credit: | Published on the OpenBSD errata list. FreeBSD credits Sebastian Krahmer <[email protected]>. |
| Vulnerable: |
OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 |
| Not Vulnerable: |
NetBSD NetBSD 1.6 |
Discussion
Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
A vulnerability has been reported in some versions of the pppd daemon included with multiple BSD distributions.
A race condition error in the code may result in the pppd process changing the file permissions on an arbitrary system file. pppd will generally run as a privileged user.
This issue has been reported in OpenBSD versions 3.0 and 3.1. Earlier versions of OpenBSD may share this vulnerability, this has not however been confirmed.
A vulnerability has been reported in some versions of the pppd daemon included with multiple BSD distributions.
A race condition error in the code may result in the pppd process changing the file permissions on an arbitrary system file. pppd will generally run as a privileged user.
This issue has been reported in OpenBSD versions 3.0 and 3.1. Earlier versions of OpenBSD may share this vulnerability, this has not however been confirmed.
Exploit / POC
Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
Sebastian Krahmer has released exploit code:
Sebastian Krahmer has released exploit code:
Solution / Fix
Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
Solution:
NetBSD has reissued their advisory. Users are strongly urged to upgrade systems to NetBSD 1.6 which is not vulnerable to this issue. Further details are available in the referenced advisory.
Patches are available:
OpenBSD OpenBSD 3.1
OpenBSD OpenBSD 3.0
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.4 -STABLE
FreeBSD FreeBSD 4.4 -RELENG
FreeBSD FreeBSD 4.5 -STABLE
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.5 -RELEASE
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.6 -RELEASE
FreeBSD FreeBSD 4.6 -STABLE
Solution:
NetBSD has reissued their advisory. Users are strongly urged to upgrade systems to NetBSD 1.6 which is not vulnerable to this issue. Further details are available in the referenced advisory.
Patches are available:
OpenBSD OpenBSD 3.1
-
OpenBSD 011_pppd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/011_pppd.patch
OpenBSD OpenBSD 3.0
-
OpenBSD 028_pppd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/028_pppd.patch
FreeBSD FreeBSD 4.4
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.4 -STABLE
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.4 -RELENG
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.5 -STABLE
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.5
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.5 -RELEASE
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.6
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.6 -RELEASE
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
FreeBSD FreeBSD 4.6 -STABLE
-
FreeBSD pppd.patch
The following commands must be executed as the root user:# cd /usr/src# patch < /path/to/patch# cd /usr/src/usr.sbin/pppd# make depend && make && make install
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:32/pppd.patch
References
Multiple Vendor BSD pppd Arbitrary File Permission Modification Race Condition Vulnerability
References:
References:
- OpenBSD 3.2 release errata & patch list (OpenBSD)