Simple Dynamic Finger Daemon (sdfingerd) Lets Local Users Obtain Root Privileges
|
|
SecurityTracker Alert ID: 1007036
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jun 23 2003
|
Impact: Execution of arbitrary code via local system, Root access via local system
|
Exploit Included: Yes
|
Version(s): 1.1
|
Description: A vulnerability was reported in the Simple Dynamic Finger Daemon (sdfingerd). A local user can gain root privileges.
vade79/v9 v9@fakehalo.deadpig.org (fakehalo) posted a demonstration exploit script for sdfingerd. The script indicates that sdfingerd
will execute commands in the fingered user's '.plan' file with the privileges of the requested user id. However, the group id privileges
are not set to that of the requested user. Because sdfingerd runs by default with root privileges, commands in the '.plan' file
can be executed with root group privileges (gid=0).
A demonstration exploit script is available at:
http://fakehalo.deadpig.org/xsdfingerd.sh
|
Impact: A local user can execute arbitrary commands with root privileges.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.schmolze.com/projects/sdfingerd/ (Links to External Site)
|
Cause: Access control error, State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 23 Jun 2003 09:53:17 -0400
Subject: sdfingerd
|
http://fakehalo.deadpig.org/xsdfingerd.sh
vade79/v9 v9@fakehalo.deadpig.org (fakehalo) posted a demonstration exploit script
regarding a vulnerability in sdfingerd version 1.1. A local user can gain root group
privileges (gid=0).
According to the report, the Simple Dynamic Finger Daemon will execute commands in the
fingered user's '.plan' file with the privileges of the requested user id. However, the
group id privileges are not set to that of the requested user. Because sdfingerd runs by
default with root privileges, commands in the '.plan' file can be executed with root group
privileges.
Vendor URL: http://www.schmolze.com/projects/sdfingerd/
Vendor: schmolze studios
|
|