FreeBSD xmindpath Buffer Overflow Vulnerability
BID:839
Info
FreeBSD xmindpath Buffer Overflow Vulnerability
| Bugtraq ID: | 839 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 01 1999 12:00AM |
| Updated: | Dec 01 1999 12:00AM |
| Credit: | First posted to BugTraq by Brock Tellier <[email protected]> on December 1, 1999. |
| Vulnerable: |
FreeBSD FreeBSD 3.3 |
| Not Vulnerable: | |
Discussion
FreeBSD xmindpath Buffer Overflow Vulnerability
The version of xmindpath shipped with FreeBSD 3.3 can be locally exploited via overrunning a buffer of predefined length. It is possible to gain the effective userid of uucp through this vulnerability. It may be possible, after attaining uucp priviliges, to modify binaries to which uucp has write access to and trojan them to further elevate priviliges), ie: modify minicom so that when root runs it, drops a suid shell somewhere.
The version of xmindpath shipped with FreeBSD 3.3 can be locally exploited via overrunning a buffer of predefined length. It is possible to gain the effective userid of uucp through this vulnerability. It may be possible, after attaining uucp priviliges, to modify binaries to which uucp has write access to and trojan them to further elevate priviliges), ie: modify minicom so that when root runs it, drops a suid shell somewhere.
Exploit / POC
FreeBSD xmindpath Buffer Overflow Vulnerability
Exploit available:
Exploit available:
Solution / Fix
FreeBSD xmindpath Buffer Overflow Vulnerability
Solution:
Remove the suid bit from the xmindpath binary.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Remove the suid bit from the xmindpath binary.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
FreeBSD xmindpath Buffer Overflow Vulnerability
References:
References: