Solaris sdtcm_convert File Creation Vulnerability
BID:575
Info
Solaris sdtcm_convert File Creation Vulnerability
| Bugtraq ID: | 575 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 09 1999 12:00AM |
| Updated: | Aug 09 1999 12:00AM |
| Credit: | First posted to BugTraq by Joel Eriksson <[email protected]> on August 9, 1999. |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.5 |
| Not Vulnerable: | |
Discussion
Solaris sdtcm_convert File Creation Vulnerability
There is a vulnerability in sdtcm_convert, a caldendar data conversion utility and one of the programs associated with the version of CDE bundled with Solaris 2.6. stdcm_convert will create files (if absent) in /usr/spool/calendar/ called .lock.convert.<hostname> and .lock.<hostname> as root, set mode 0660 (owned by root, group-owned by user's (your) group, and group writeable). If these files do not already exist, it is possible to create a symlink pointed to any file in the filesystem which will be created and be writeable by the attacker. The consequences of this is a possible local root compromise. The vulnerability cannot be used to overwrite already existing files.
There is a vulnerability in sdtcm_convert, a caldendar data conversion utility and one of the programs associated with the version of CDE bundled with Solaris 2.6. stdcm_convert will create files (if absent) in /usr/spool/calendar/ called .lock.convert.<hostname> and .lock.<hostname> as root, set mode 0660 (owned by root, group-owned by user's (your) group, and group writeable). If these files do not already exist, it is possible to create a symlink pointed to any file in the filesystem which will be created and be writeable by the attacker. The consequences of this is a possible local root compromise. The vulnerability cannot be used to overwrite already existing files.
Exploit / POC
Solaris sdtcm_convert File Creation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Solaris sdtcm_convert File Creation Vulnerability
Solution:
A quick solution is to remove the setuid bit from sdtcm_convert or remove/disable the program completely.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Sun Solaris 2.6
Sun Solaris 2.6_x86
Sun Solaris 2.5
Sun Solaris 2.5_x86
Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
Solution:
A quick solution is to remove the setuid bit from sdtcm_convert or remove/disable the program completely.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Sun Solaris 2.6
-
Sun 105566-06
sparc
http://sunsolve.sun.com/search/document.do?assetkey=1-21-105566-06-1
Sun Solaris 2.6_x86
-
Sun 105567-07
x86
http://sunsolve.sun.com/search/document.do?assetkey=1-21-105567-07-1
Sun Solaris 2.5
Sun Solaris 2.5_x86
Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
References
Solaris sdtcm_convert File Creation Vulnerability
References:
References: