Multiple Vendor suidperl Overflow Vulnerability
BID:708
Info
Multiple Vendor suidperl Overflow Vulnerability
| Bugtraq ID: | 708 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 17 1997 12:00AM |
| Updated: | Apr 17 1997 12:00AM |
| Credit: | The vulnerability was discovered by Willy Tarreau <[email protected]> and reported to Bugtraq by Jason T. Murphy <[email protected]> on 17 April 1997. On 13 November 1997 Pavel Kankovsky <[email protected]> posted anothe |
| Vulnerable: |
SGI Freeware 2.0 SGI Freeware 1.0 Redhat Linux 4.2 Redhat Linux 4.1 Redhat Linux 4.0 Larry Wall Perl 5.0 03 BSDI BSD/OS 3.0 BSDI BSD/OS 2.1 |
| Not Vulnerable: |
Larry Wall Perl 5.0 04 |
Discussion
Multiple Vendor suidperl Overflow Vulnerability
Several buffer overflows were found in the Perl helper application 'suidperl' or 'sperl'. When this program is installed setuid root the overflows may lead to a local root compromise.
Several buffer overflows were found in the Perl helper application 'suidperl' or 'sperl'. When this program is installed setuid root the overflows may lead to a local root compromise.
Exploit / POC
Multiple Vendor suidperl Overflow Vulnerability
The exploit sperlexp.tgz (see below) was written by Willy Tarreau <[email protected]> and posted to Bugtraq on 17 April 1997.
The suidperl.pl exploit for Redhat 4.2 by Pavel Kankovsky <[email protected]> was posted to bugtraq on 13 November 1997 by Pavel
The exploit sperlexp.tgz (see below) was written by Willy Tarreau <[email protected]> and posted to Bugtraq on 17 April 1997.
The suidperl.pl exploit for Redhat 4.2 by Pavel Kankovsky <[email protected]> was posted to bugtraq on 13 November 1997 by Pavel
Solution / Fix
Multiple Vendor suidperl Overflow Vulnerability
Solution:
It is very much advised to the latest version of Perl 5. Another possibility is to install a vendor supplied patch or remove the setuid bit from the 'suidperl' or 'sperl' executable.
Solution:
It is very much advised to the latest version of Perl 5. Another possibility is to install a vendor supplied patch or remove the setuid bit from the 'suidperl' or 'sperl' executable.