Platform Load Sharing Facility LSF_ENVDIR Local Command Execution Vulnerability
BID:7655
Info
Platform Load Sharing Facility LSF_ENVDIR Local Command Execution Vulnerability
| Bugtraq ID: | 7655 |
| Class: | Environment Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 22 2003 12:00AM |
| Updated: | May 22 2003 12:00AM |
| Credit: | Discovery credited to Tomasz Grabowski <[email protected]>. |
| Vulnerable: |
Platform LSF 5.1 Platform LSF 5.0 Platform LSF 4.2 Platform LSF 4.0 |
| Not Vulnerable: | |
Discussion
Platform Load Sharing Facility LSF_ENVDIR Local Command Execution Vulnerability
It has been reported that Load Sharing Facility (LSF) does not properly handle input in environment variables. Because of this, an attacker may be able to gain escalated privileges on a vulnerable system.
It has been reported that Load Sharing Facility (LSF) does not properly handle input in environment variables. Because of this, an attacker may be able to gain escalated privileges on a vulnerable system.
Exploit / POC
Platform Load Sharing Facility LSF_ENVDIR Local Command Execution Vulnerability
This exploit was contributed by Tomasz Grabowski <[email protected]>:
This exploit was contributed by Tomasz Grabowski <[email protected]>:
Solution / Fix
Platform Load Sharing Facility LSF_ENVDIR Local Command Execution Vulnerability
Solution:
A vendor supplied fix has been released to address this issue. The following details have been supplied:
Patch info: sup_by_dev33993
FTP Server: ftp.platform.com
Path to patches: patches/<version>/os/<os>/lsadmin*
Example: patches/5.1/os/sparc-sol7-64/lsadmin5.1_sparc-sol7-64.Z
The vendor has advised that unavailable versions can be built on demand. Customers are advised to contact Platform Technical Support ([email protected]) for further information.
Solution:
A vendor supplied fix has been released to address this issue. The following details have been supplied:
Patch info: sup_by_dev33993
FTP Server: ftp.platform.com
Path to patches: patches/<version>/os/<os>/lsadmin*
Example: patches/5.1/os/sparc-sol7-64/lsadmin5.1_sparc-sol7-64.Z
The vendor has advised that unavailable versions can be built on demand. Customers are advised to contact Platform Technical Support ([email protected]) for further information.
References
Platform Load Sharing Facility LSF_ENVDIR Local Command Execution Vulnerability
References:
References:
- Platform Homepage (Platform)
- Security advisory: LSF 5.1 local root exploit (Tomasz Grabowski
)