Rational ClearCase SUID Vulnerability
BID:538
Info
Rational ClearCase SUID Vulnerability
| Bugtraq ID: | 538 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 08 1999 12:00AM |
| Updated: | Feb 08 1999 12:00AM |
| Credit: | Reported by Mudge <[email protected]> in a L0pht Security Advisory released Feb 8 1999. |
| Vulnerable: |
Rational Software ClearCase for Unix 3.2 |
| Not Vulnerable: | |
Discussion
Rational ClearCase SUID Vulnerability
Rational Software's ClearCase product includes a vulnerability whereby an unprivileged user can have any readable executable set to SUID root.. A 1.5 meg file is copied and then chmod'ed to SUID, and during the time this file is being copied it can be unlinked and replaced with another.
Rational Software's ClearCase product includes a vulnerability whereby an unprivileged user can have any readable executable set to SUID root.. A 1.5 meg file is copied and then chmod'ed to SUID, and during the time this file is being copied it can be unlinked and replaced with another.
Solution / Fix
Rational ClearCase SUID Vulnerability
Solution:
Rational has provided a patch, available only to registered users. It is at:
http://clearcase.rational.com/techsupport/clearcase/tech/patchlink/clearcase
Solution:
Rational has provided a patch, available only to registered users. It is at:
http://clearcase.rational.com/techsupport/clearcase/tech/patchlink/clearcase
References
Rational ClearCase SUID Vulnerability
References:
References:
- L0pht Heavy Industries Advisories (L0pht Heavy Industries)