20020422 Pine Internet Advisory: Setuid application execution may give local root in FreeBSDmailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0033.html CVE-2002-0572
Apple Mac OSX 10.x / FreeBSD 4.x / OpenBSD 2.x / Solaris 2.5/2.6/7.0/8 - 'exec C Library' Standard I/O File Descriptor Closure
Record summary
CVE-2002-0572 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApple Mac OSX 10.x / FreeBSD 4.x / OpenBSD 2.x / Solaris 2.5/2.6/7.0/8 - 'exec C Library' Standard I/O File Descriptor ClosureExploitDB exploitby phasedNot analyzed1 file
References
920020422 Pine Internet Advisory: Setuid application execution may give local root in FreeBSDmailing list
http://online.securityfocus.com/archive/1/268970 20020423 cheersmailing list
http://online.securityfocus.com/archive/1/269102 M-072Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/m-072.shtml bsd-suid-apps-gain-privileges(8920)vdb entry
http://www.iss.net/security_center/static/8920.php VU#809347Third-party advisory
http://www.kb.cert.org/vuls/id/809347 6095vdb entry
http://www.osvdb.org/6095 4568vdb entry
http://www.securityfocus.com/bid/4568 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0572