Sun Solaris AT Command Race Condition Vulnerability
BID:6693
Info
Sun Solaris AT Command Race Condition Vulnerability
| Bugtraq ID: | 6693 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 27 2003 12:00AM |
| Updated: | Jan 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Wojciech Purczynski <[email protected]>. |
| Vulnerable: |
Sun Solaris 2.5.1 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5 |
| Not Vulnerable: | |
Discussion
Sun Solaris AT Command Race Condition Vulnerability
The at utility shipped with Sun Solaris may be prone to an issue which may allow unprivileged users to delete any file on the vulnerable system.
This vulnerability is a consequence of the issue described in BID 6692 and also occurs when at is used with the -r commandline option.
at is prone to a race condition vulnerability when verifying the ownership of an at job before deletion. This issue may result in the deletion of a file other than the expected at job. As the at binary is typically installed setuid root, this may allow an attacker to delete arbitrary system files.
The at utility shipped with Sun Solaris may be prone to an issue which may allow unprivileged users to delete any file on the vulnerable system.
This vulnerability is a consequence of the issue described in BID 6692 and also occurs when at is used with the -r commandline option.
at is prone to a race condition vulnerability when verifying the ownership of an at job before deletion. This issue may result in the deletion of a file other than the expected at job. As the at binary is typically installed setuid root, this may allow an attacker to delete arbitrary system files.
Exploit / POC
Sun Solaris AT Command Race Condition Vulnerability
The following exploit was provided:
The following exploit was provided:
Solution / Fix
Sun Solaris AT Command Race Condition Vulnerability
Solution:
The vendor has supplied the following fixes:
Sun Solaris 2.6
Sun Solaris 7.0
Sun Solaris 8_x86
Sun Solaris 2.6_x86
Sun Solaris 8_sparc
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 7.0_x86
Solution:
The vendor has supplied the following fixes:
Sun Solaris 2.6
Sun Solaris 7.0
Sun Solaris 8_x86
-
Sun 108876-13
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=108876&rev=13 -
Sun 109008-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=109008&rev=09
Sun Solaris 2.6_x86
Sun Solaris 8_sparc
-
Sun 108875-13
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=108875&rev=13 -
Sun 109007-09
http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchId=109007&rev=09
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 7.0_x86
References
Sun Solaris AT Command Race Condition Vulnerability
References:
References:
- Security Vulnerability with the at(1) Command on Solaris (Sun Microsystems)
- Sun Microsystems Solaris at -r job name handling and race condition (Wojciech Purczynski
)