olaris /opt/JSparm/bin/perfmon程序创建根目录文件漏洞

olaris /opt/JSparm/bin/perfmon程序创建根目录文件漏洞

漏洞ID 1106262 漏洞类型 未知
发布时间 2001-03-23 更新时间 2001-06-18
图片[1]-olaris /opt/JSparm/bin/perfmon程序创建根目录文件漏洞-安全小百科CVE编号 CVE-2001-0403
图片[2]-olaris /opt/JSparm/bin/perfmon程序创建根目录文件漏洞-安全小百科CNNVD-ID CNNVD-200106-099
漏洞平台 Solaris CVSS评分 7.2
|漏洞来源
https://www.exploit-db.com/exploits/20715
https://www.securityfocus.com/bid/88807
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200106-099
|漏洞详情
Solaris/opt/JSparm/bin/perfmon程序存在漏洞。本地用户可以借助GUI的登录文件选项创建任意根目录文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/2515/info

JSparm is the Junsoft Performance Analysis Report Maker package. This software package provides an enhanced perfmon performance monitoring package and interface, as well as a performance report generation interface.

A problem with the package could make it possible for a user with local access to overwrite any file on the system. It is possible for a user to launch the perfmon program from the command line interface, and create a logfile of activity monitored by the perfmon package. The user may specify the file in which the activity should be logged. Insufficient checking of file permissions, as well as the program being SUID, make it possible for the log file to be any file on the system. The file created/overwritten is set to mode 0666.

Therefore, it is possible for a user with local access to overwrite sensitive system files, and gain elevated privileges. 


$ whoami
loveyou
$ umask 0000
$ /opt/JSparm/bin/perfmon &

Choose Logging -> Logging File
In Selection part, input the file path you want to create
ex: /.rhosts

Following file is created in a second.
-rw-rw-rw- 1 root loveyou 144 Mar 9 03:14 .rhost
|受影响的产品
Sun Solaris 2.0
|参考资料

来源:BUGTRAQ
名称:20010323[Hackerslabbug_paper]SunOSapplicationperfmonvulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2001-03/0326.html
来源:XF
名称:solaris-perfmon-create-files
链接:http://xforce.iss.net/static/6267.php

相关推荐: Solaris libnsl rpcbind拒绝服务漏洞

Solaris libnsl rpcbind拒绝服务漏洞 漏洞ID 1207328 漏洞类型 未知 发布时间 1998-07-15 更新时间 1998-07-15 CVE编号 CVE-1999-0213 CNNVD-ID CNNVD-199807-014 漏洞…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享