net-acct Unsafe Temporary File May Let Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1011172 |
|
SecurityTracker URL: http://securitytracker.com/id/1011172
|
|
CVE Reference:
CAN-2004-0851
(Links to External Site)
|
Updated: Oct 6 2004
|
Original Entry Date: Sep 7 2004
|
Impact:
Modification of system information, Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 0.71 and prior versions
|
Description:
A vulnerability was reported in net-acct. A local user may be able to obtain elevated privileges.
The vendor reported that the software creates a temporary file in an unsafe manner. The software creates '/tmp/nacctd.write.[pid]' and then later deletes the file. A local user can create a symbolic link (symlink) from a critical file on the system to the temporary filename to be used. Then, when net-acct is run, the symlinked file may be overwritten or deleted with the privileges of the net-acct process.
The vendor credits Stefan Nordhausen with discovering this flaw.
|
Impact:
A local user may be able to obtain elevated privileges.
|
Solution:
The vendor has released the following patch:
http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
|
Vendor URL: exorsus.net/projects/net-acct/ (Links to External Site)
|
Cause:
Access control error, State error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 7 Sep 2004 13:58:07 -0400
Subject: http://exorsus.net/projects/net-acct/
|
> News (last updated Sep 2 2004)
>
> SECURITY: Stefan Nordhausen has identified a local security hole in net-acct (all
> versions). It appears to be some redundant code from some time way back in the past
> although I'm not entirely sure. I have removed the code, since it doesn't actually
> appear to do anything other than create and delete a file that is referenced nowhere
> else. Use the patch at your own risk, until I've had some feedback telling me it
> works.
>
> net-acct-notempfiles.patch
http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
|
|