SCO OpenServer Doctor Command Execution Vulnerability
BID:621
Info
SCO OpenServer Doctor Command Execution Vulnerability
| Bugtraq ID: | 621 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Sep 09 1999 12:00AM |
| Updated: | Sep 09 1999 12:00AM |
| Credit: | This vulnerability was posted ot the Bugtraq mailinst list by Brock Tellier" <[email protected]> on Tue Sep 07 1999. |
| Vulnerable: |
SCO Open Server 5.0.5 SCO Open Server 5.0.4 |
| Not Vulnerable: | |
Discussion
SCO OpenServer Doctor Command Execution Vulnerability
The SCO Doctor management tool allows any user to execute commands with root privileges. The SCO Doctor management tool autonomously monitors and manages systems to ensure optimum reliability and performance. SCO DOctor ships with SCO OpenServer.
By default /bin/doctor is SUID root and world executable.
The SCO Doctor management tool allows any user to execute commands with root privileges. The SCO Doctor management tool autonomously monitors and manages systems to ensure optimum reliability and performance. SCO DOctor ships with SCO OpenServer.
By default /bin/doctor is SUID root and world executable.
Exploit / POC
SCO OpenServer Doctor Command Execution Vulnerability
The "Command Execution" menu option under "Tools" allows you to run any command you wish with root privileges.
The "Command Execution" menu option under "Tools" allows you to run any command you wish with root privileges.
Solution / Fix
SCO OpenServer Doctor Command Execution Vulnerability
Solution:
To mitigate this vulnerability, change the permissions on /bin/doctor to 700.
Solution:
To mitigate this vulnerability, change the permissions on /bin/doctor to 700.
References
SCO OpenServer Doctor Command Execution Vulnerability
References:
References: