Progress Database Error Message File Disclosure Vulnerability
BID:7273
Info
Progress Database Error Message File Disclosure Vulnerability
| Bugtraq ID: | 7273 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 03 2003 12:00AM |
| Updated: | Apr 03 2003 12:00AM |
| Credit: | Discovery is credited to KF <[email protected]>. |
| Vulnerable: |
Progress Database 9.1 D Progress Database 9.1 C Progress Database 9.1 B Progress Database 8.3 V Progress Database 8.3 E Progress Database 8.3 D |
| Not Vulnerable: | |
Discussion
Progress Database Error Message File Disclosure Vulnerability
Some Progress Database binaries are reportedly installed setuid root on Unix systems. It is possible for a local user to specify an arbitrary path to a configuration file via environment variables, which will be accessed with elevated privileges. If an error is encountered when opening the configuration file, the contents of the file are displayed in the error message.
This could allow an unprivileged user to specify any file as the configuration file and view the contents through the Progress error message regardless of the privilege level of the target file.
Some Progress Database binaries are reportedly installed setuid root on Unix systems. It is possible for a local user to specify an arbitrary path to a configuration file via environment variables, which will be accessed with elevated privileges. If an error is encountered when opening the configuration file, the contents of the file are displayed in the error message.
This could allow an unprivileged user to specify any file as the configuration file and view the contents through the Progress error message regardless of the privilege level of the target file.
Exploit / POC
Progress Database Error Message File Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Progress Database Error Message File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Progress Database Error Message File Disclosure Vulnerability
References:
References: