Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-5899. PoCs published by bcoles.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in s-nail's privsep helper (CVE-2017-5899) to achieve local privilege escalation via a race condition and ld.so.preload manipulation. It compiles a shared library to escalate privileges and spawns a root shell.
Description
Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
Exploits (1)
This exploit leverages a directory traversal vulnerability in s-nail's privsep helper (CVE-2017-5899) to achieve local privilege escalation via a race condition and ld.so.preload manipulation. It compiles a shared library to escalate privileges and spawns a root shell.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H