HP-UX NLSPATH Environment Variable Format String Vulnerability
BID:8985
Info
HP-UX NLSPATH Environment Variable Format String Vulnerability
| Bugtraq ID: | 8985 |
| Class: | Design Error |
| CVE: |
CVE-2003-0090 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 05 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to NSFocus. |
| Vulnerable: |
HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.20 |
| Not Vulnerable: | |
Discussion
HP-UX NLSPATH Environment Variable Format String Vulnerability
HP-UX allows the NLSPATH to be set for setuid root programs, which use catopen(3C) and may be executed by other local users. This could result in privilege escalation as an attacker could specify an arbitrary path for a message catalogue, which will be opened with elevated privileges.
HP-UX allows the NLSPATH to be set for setuid root programs, which use catopen(3C) and may be executed by other local users. This could result in privilege escalation as an attacker could specify an arbitrary path for a message catalogue, which will be opened with elevated privileges.
Exploit / POC
HP-UX NLSPATH Environment Variable Format String Vulnerability
The following proof of concept exploit was supplied by [email protected]:
The following proof of concept exploit was supplied by [email protected]:
Solution / Fix
HP-UX NLSPATH Environment Variable Format String Vulnerability
Solution:
HP has released a revised advisory (SSRT3656) and the following patches to address this issue:
HP HP-UX 10.20
HP HP-UX 11.0
HP HP-UX 11.0 4
HP HP-UX 11.11
HP HP-UX 11.22
Solution:
HP has released a revised advisory (SSRT3656) and the following patches to address this issue:
HP HP-UX 10.20
-
HP PHCO_26158
http://itrc.hp.com
HP HP-UX 11.0
-
HP PHCO_29284
http://itrc.hp.com
HP HP-UX 11.0 4
-
HP PHCO_30191
http://itrc.hp.com
HP HP-UX 11.11
-
HP PHCO_29495
http://itrc.hp.com
HP HP-UX 11.22
-
HP PHCO_29329
http://itrc.hp.com
References
HP-UX NLSPATH Environment Variable Format String Vulnerability
References:
References:
- NSFOCUS SA2003-08: HP-UX libc NLSPATH Environment Variable Privilege Elevation V (NSFOCUS Security Team
)