SCO Unixware pis/mkpis Symbolic Link Vulnerability
BID:901
Info
SCO Unixware pis/mkpis Symbolic Link Vulnerability
| Bugtraq ID: | 901 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 27 1999 12:00AM |
| Updated: | Dec 27 1999 12:00AM |
| Credit: | First posted to Brock Tellier <[email protected]> on December 27, 1999. |
| Vulnerable: |
SCO Unixware 7.1 |
| Not Vulnerable: | |
Discussion
SCO Unixware pis/mkpis Symbolic Link Vulnerability
It is possible to create arbitrary files owned by group sys through exploiting symlink vulnerabilities in UnixWare's mkpis and pis binaries. mkpis/pis will create a temporary file (/tmp/pisdata) owned by group sys when run, without determining whether the temporary file exists already and/or links to other places. mkpis/pis will follow syminks and overwrite files linked to where possible. /sbin is writeable by group sys, making it possible to overwrite certain binaries with malicious versions to be executed by root (/sbin is first in $PATH) at a later time possibly leading to a system-wide compromise.
It is possible to create arbitrary files owned by group sys through exploiting symlink vulnerabilities in UnixWare's mkpis and pis binaries. mkpis/pis will create a temporary file (/tmp/pisdata) owned by group sys when run, without determining whether the temporary file exists already and/or links to other places. mkpis/pis will follow syminks and overwrite files linked to where possible. /sbin is writeable by group sys, making it possible to overwrite certain binaries with malicious versions to be executed by root (/sbin is first in $PATH) at a later time possibly leading to a system-wide compromise.