Cobalt RaQ2 cgiwrap Vulnerability
BID:777
Info
Cobalt RaQ2 cgiwrap Vulnerability
| Bugtraq ID: | 777 |
| Class: | Environment Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 08 1999 12:00AM |
| Updated: | Nov 08 1999 12:00AM |
| Credit: | This was posted to BugTraq by Chris Adams <[email protected]> on Nov 8, 1999. |
| Vulnerable: |
Cobalt RaQ 2.0 |
| Not Vulnerable: | |
Discussion
Cobalt RaQ2 cgiwrap Vulnerability
Cobalt RaQ2 servers come with a program called "cgiwrap", which acts as a wrapper for cgi programs so that they run with the uid of their user instead of ' nobody'. It may be possible to cause a denial of service to websites hosted on the server or compromise web data.
cgiwrap interprets subdirectories of web/ in which cgi scripts are run as user directories, and if a user is created which happens to have the same name as the directory which scripts run from - cgiwrap will try to run a file that doesn't exist in that user's directory. In a worse case, a script can be substituted and important data submitted to web forms compromised.
Cobalt RaQ2 servers come with a program called "cgiwrap", which acts as a wrapper for cgi programs so that they run with the uid of their user instead of ' nobody'. It may be possible to cause a denial of service to websites hosted on the server or compromise web data.
cgiwrap interprets subdirectories of web/ in which cgi scripts are run as user directories, and if a user is created which happens to have the same name as the directory which scripts run from - cgiwrap will try to run a file that doesn't exist in that user's directory. In a worse case, a script can be substituted and important data submitted to web forms compromised.
Exploit / POC
Cobalt RaQ2 cgiwrap Vulnerability
See discussion.
See discussion.
Solution / Fix
Cobalt RaQ2 cgiwrap Vulnerability
Solution:
Cobalt has released patches to adress this problem. The patches are available from the following locations:
Cobalt Networks is dedicated to providing secure platforms.
Accordingly, we have just completed a fix for this bug that is available
in RPM format, which can be found at the following locations:
RaQ 3i (x86)
RPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/rpms/cgiwrap-pacifica-3.6.4.C5.i386.rpm
SRPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/srpms/cgiwrap-pacifica-3.6.4.C5.src.rpm
RaQ 2 (MIPS)
RPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/rpms/cgiwrap-raq2-3.6.4.C5.mips.rpm
SRPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/srpms/cgiwrap-raq2-3.6.4.C5.src.rpm
Cobalt also included the following information in their release:
MD5 sum Package Name
--------------------------------------------------------------------------
701b43ba607edee44c684ac2d428e710 cgiwrap-pacifica-3.6.4.C5.i386.rpm
41b7277afefb199c01a212dc86dab05b cgiwrap-pacifica-3.6.4.C5.src.rpm
0484a11647a3700fa0b9afe431c55d19 cgiwrap-raq2-3.6.4.C5.mips.rpm
5f3b483c352d25b3b11d266811e8b933 cgiwrap-raq2-3.6.4.C5.src.rpm
You can verify each rpm using the following command:
rpm --checksig [package]
To install, use the following command, while logged in as root:
rpm -U [package]
The package file format (pkg) for this fix is currently in testing, and
will be available in the very near future.
Solution:
Cobalt has released patches to adress this problem. The patches are available from the following locations:
Cobalt Networks is dedicated to providing secure platforms.
Accordingly, we have just completed a fix for this bug that is available
in RPM format, which can be found at the following locations:
RaQ 3i (x86)
RPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/rpms/cgiwrap-pacifica-3.6.4.C5.i386.rpm
SRPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/srpms/cgiwrap-pacifica-3.6.4.C5.src.rpm
RaQ 2 (MIPS)
RPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/rpms/cgiwrap-raq2-3.6.4.C5.mips.rpm
SRPM:
ftp://ftp.cobaltnet.com/pub/experimental/secuirty/srpms/cgiwrap-raq2-3.6.4.C5.src.rpm
Cobalt also included the following information in their release:
MD5 sum Package Name
--------------------------------------------------------------------------
701b43ba607edee44c684ac2d428e710 cgiwrap-pacifica-3.6.4.C5.i386.rpm
41b7277afefb199c01a212dc86dab05b cgiwrap-pacifica-3.6.4.C5.src.rpm
0484a11647a3700fa0b9afe431c55d19 cgiwrap-raq2-3.6.4.C5.mips.rpm
5f3b483c352d25b3b11d266811e8b933 cgiwrap-raq2-3.6.4.C5.src.rpm
You can verify each rpm using the following command:
rpm --checksig [package]
To install, use the following command, while logged in as root:
rpm -U [package]
The package file format (pkg) for this fix is currently in testing, and
will be available in the very near future.
References
Cobalt RaQ2 cgiwrap Vulnerability
References:
References:
- Cobalt Networks Security Information (Cobalt Networks)
- Cobalt Security Releases (Cobalt Networks)