RedHat Linux csh/tcsh Vulnerability
BID:785
Info
RedHat Linux csh/tcsh Vulnerability
| Bugtraq ID: | 785 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 08 1999 12:00AM |
| Updated: | Nov 08 1999 12:00AM |
| Credit: | This vulnerability was published in RedHat security advisory RHSA-1999:052-01 on Nov 8, 1999. |
| Vulnerable: |
Redhat Linux 6.1 i386 |
| Not Vulnerable: | |
Discussion
RedHat Linux csh/tcsh Vulnerability
It may be possible to execute arbitrary commands as a user upon their login if they are using csh/tcsh. The problem has to do with the init scripts for these shells that run when the user logs in and a /tmp race condition which they are vulnerable to.
It may be possible to execute arbitrary commands as a user upon their login if they are using csh/tcsh. The problem has to do with the init scripts for these shells that run when the user logs in and a /tmp race condition which they are vulnerable to.
Exploit / POC
RedHat Linux csh/tcsh Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RedHat Linux csh/tcsh Vulnerability
Solution:
Intel:
ftp://updates.redhat.com/6.1/i386/initscripts-4.63-1.i386.rpm
Source packages:
ftp://updates.redhat.com/6.1/SRPMS/initscripts-4.63-1.src.rpm
Solution:
Intel:
ftp://updates.redhat.com/6.1/i386/initscripts-4.63-1.i386.rpm
Source packages:
ftp://updates.redhat.com/6.1/SRPMS/initscripts-4.63-1.src.rpm