BSDI Squid File Owner Error Vulnerability
BID:89
Info
BSDI Squid File Owner Error Vulnerability
| Bugtraq ID: | 89 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | May 07 1998 12:00AM |
| Updated: | May 07 1998 12:00AM |
| Credit: | This vulnerability was published in BugTraq by Jonathan A. Zdziarski <[email protected]> on Thu, 7 May 1998. |
| Vulnerable: |
BSDI BSD/OS 4.0 |
| Not Vulnerable: | |
Discussion
BSDI Squid File Owner Error Vulnerability
By default BSDI 3.1 installs the SQUID software files owned by user 'www'. This is the same user that the web server runs user's CGI by default. This means an user could write a CGI program which can execute as user 'www' and modify SQUID files. In particular they could modify the start-squid script. This script is runned by the root user when starting SQUID. By modifing this file an attacker can execute commands as root.
By default BSDI 3.1 installs the SQUID software files owned by user 'www'. This is the same user that the web server runs user's CGI by default. This means an user could write a CGI program which can execute as user 'www' and modify SQUID files. In particular they could modify the start-squid script. This script is runned by the root user when starting SQUID. By modifing this file an attacker can execute commands as root.
Exploit / POC
BSDI Squid File Owner Error Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BSDI Squid File Owner Error Vulnerability
Solution:
Change the ownership of SQUID files to root.
Solution:
Change the ownership of SQUID files to root.