|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
Multiple versions of UNIX contain a flaw that may allow a local attacker to gain increased privileges. The issue is due to the system not applying secure permissions on core files created by SGID-only programs. By forcing a SGID binary to dump core, the resulting core file will inheret the SGID permissions and allow an unprivileged user to write to the file. This can be used to substitute the file contents with arbitrary commands that can be run with increased privileges.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to a version of Unix distributed in the last five years, as most (if not all) have fixed this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
BSD
 |
4.1 |
|
UNIX-V7
 |
Unknown or Unspecified |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|