20001028 tcsh: unsafe tempfile in << redirectsmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html CVE-2000-1134
Apple Mac OSX 10 / HP-UX 9/10/11 / Mandriva 6/7 / RedHat 5/6 / SCO 5 / IRIX 6 - Shell Redirection Race Condition
Record summary
CVE-2000-1134 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.
Description
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBApple Mac OSX 10 / HP-UX 9/10/11 / Mandriva 6/7 / RedHat 5/6 / SCO 5 / IRIX 6 - Shell Redirection Race ConditionExploitDB exploitby protonNot analyzed1 file
ExploitDBUUCP - File Creation/Overwriting SymlinksExploitDB exploitby t--zenNot analyzed1 file
References
Showing 12 of 18SSRT1-41UVendor advisory
http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html CLA-2000:350Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000350 CLSA-2000:354Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000354 20001130 [ADV/EXP]: RH6.x root from bash /tmp vuln + MOREmailing list
http://marc.info/?l=bugtraq&m=97561816504170&w=2 CSSA-2000-042.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt CSSA-2000-043.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt 20001111aVendor advisory
http://www.debian.org/security/2000/20001111a VU#10277Third-party advisory
http://www.kb.cert.org/vuls/id/10277 MDKSA-2000-069Vendor advisory
http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3 MDKSA-2000:075Vendor advisory
http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3 RHSA-2000:117Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-117.html