NetBSD Trek Local Buffer Overflow Vulnerability
BID:6036
Info
NetBSD Trek Local Buffer Overflow Vulnerability
| Bugtraq ID: | 6036 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1543 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 24 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to Niels Heinen. |
| Vulnerable: |
NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 |
| Not Vulnerable: | |
Discussion
NetBSD Trek Local Buffer Overflow Vulnerability
Trek is a game included with NetBSD. Games are invoked by the /usr/games/dm binary, which is setgid games by default. Normal game behaviour involves revoking privileges. Trek fails to drop privileges, potentially resulting in privilege escalation.
A buffer overflow has been discovered in Trek. By passing a string of excessive length to Trek, it may be possible to corrupt sensitive memory values and obtain 'games' privileges.
It should be noted that NetBSD 1.6 does not use 'dm' to execute games, thus it may not be possible to obtain 'games' privileges by exploiting this vulnerability.
Trek is a game included with NetBSD. Games are invoked by the /usr/games/dm binary, which is setgid games by default. Normal game behaviour involves revoking privileges. Trek fails to drop privileges, potentially resulting in privilege escalation.
A buffer overflow has been discovered in Trek. By passing a string of excessive length to Trek, it may be possible to corrupt sensitive memory values and obtain 'games' privileges.
It should be noted that NetBSD 1.6 does not use 'dm' to execute games, thus it may not be possible to obtain 'games' privileges by exploiting this vulnerability.
Exploit / POC
NetBSD Trek Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NetBSD Trek Local Buffer Overflow Vulnerability
Solution:
NetBSD has released an advisory.
Users of NetBSD-current are advised to upgrade to NetBSD-current dated 2002-10-19 or later.
Users of NetBSD 1.6 are advised to upgrade from NetBSD 1.6 sources dated 2002-10-22 or later.
Users of NetBSD 1.5 through 1.5.3 from NetBSD 1.5.* sources dated 2002-10-19 or later.
Further details are available in the referenced advisory.
Solution:
NetBSD has released an advisory.
Users of NetBSD-current are advised to upgrade to NetBSD-current dated 2002-10-19 or later.
Users of NetBSD 1.6 are advised to upgrade from NetBSD 1.6 sources dated 2002-10-22 or later.
Users of NetBSD 1.5 through 1.5.3 from NetBSD 1.5.* sources dated 2002-10-19 or later.
Further details are available in the referenced advisory.
References
NetBSD Trek Local Buffer Overflow Vulnerability
References:
References: