Remstats Lets Local Users Gain Elevated Privileges and Remote Users Execute Arbitrary Commands
|
|
SecurityTracker Alert ID: 1013646 |
|
SecurityTracker URL: http://securitytracker.com/id/1013646
|
|
CVE Reference:
CAN-2005-0387, CAN-2005-0388
(Links to External Site)
|
Date: Apr 5 2005
|
Impact:
Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via local system, User access via network
|
|
Version(s): 1.0.13a and prior versions
|
Description:
Two vulnerabilities were reported in Remstats. A local user can gain elevated privileges. A remote user can execute arbitrary commands on the target system.
The software creates a temporary debug file '/tmp/uptimes' in an unsafe manner [CVE: CAN-2005-0387]. A local user can create a symbolic link from a critical file on the system to the temporary file. Then, when Remstats is run by the target user, the symlinked file may be created or overwritten with the privileges of the target user.
The flaw resides in 'unix-status-server.pl'.
A remote user can connect to the remoteping service and supply a specially crafted (and invalid) IP number to execute arbitrary commands on the target system [CVE: CAN-2005-0388].
The flaw resides in 'remoteping-server.pl'
Jens Steube is credited with discovering these vulnerabilities.
|
Impact:
A local user can gain elevated privileges.
A remote user can execute arbitrary commands on the target system.
|
Solution:
No solution was available at the time of this entry.
|
Vendor URL: remstats.sourceforge.net/release/index.html (Links to External Site)
|
Cause:
Access control error, Input validation error, State error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 5 Apr 2005 01:52:33 -0400
Subject: [none]
|
Debian reported:
Jens Steube discovered several vulnerabilities in remstats, the remote
statistics system. The Common Vulnerabilities and Exposures Project
identifies the following problems:
CAN-2005-0387
When processing uptime data on the unix-server a temporary file is
opened in an insecure fashion which could be used for a symlink
attack to create or overwrite arbitrary files with the permissions
of the remstats user.
CAN-2005-0388
The remoteping service can be exploited to execute arbitrary
commands due to missing input sanitising.
|
|