Oracle for Linux安装漏洞

Oracle for Linux安装漏洞

漏洞ID 1105738 漏洞类型 竞争条件
发布时间 2000-03-05 更新时间 2005-05-02
图片[1]-Oracle for Linux安装漏洞-安全小百科CVE编号 CVE-2000-0206
图片[2]-Oracle for Linux安装漏洞-安全小百科CNNVD-ID CNNVD-200003-012
漏洞平台 Linux CVSS评分 6.2
|漏洞来源
https://www.exploit-db.com/exploits/19794
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200003-012
|漏洞详情
LinuxOracle8.1.5.x版本的安装跟随符号链接并创建全局可读许可的orainstRoot.sh文件。本地用户利用此漏洞提升特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/1035/info

A vulnerability exists in the installation program for Oracle 8.1.5i. The Oracle installation scripts will create a directory named /tmp/orainstall, owned by oracle:dba, mode 711. Inside of this directory it will create a shell script named orainstRoot.sh, mode 777. The installation script will then stop and ask the person installing to run this script. The installation program at no point attempts to determine if the directory or script already exist. This makes it possible to create a symbolic link from the orainstRoot.sh file to elsewhere on the file system. This could be used to create a .rhosts file, for instance, and gain access to the root account. In addition, since the orainstRoot.sh file is mode 777, it is possible for any user on the machine to edit this script to execute arbitrary commands when run by root. Again, this can result in the compromise of the root account.

It is not readily apparent what versions of Oracle this does and does not affect. It has been confirmed on Oracle 8.1.5i, on the Linux/Intel platform. 

mkdir /tmp/orainstall
ln -sf /.rhosts /tmp/orainstall/orainstRoot.sh
|参考资料

来源:BID
名称:1035
链接:http://www.securityfocus.com/bid/1035
来源:BUGTRAQ
名称:20000305Oracleinstallerproblem
链接:http://archives.neohapsis.com/archives/bugtraq/2000-03/0023.html

相关推荐: Symantec Norton AntiVirus NULL Characters Incoming Email Protection Bypass Vulnerability

Symantec Norton AntiVirus NULL Characters Incoming Email Protection Bypass Vulnerability 漏洞ID 1102375 漏洞类型 Design Error 发布时间 2002-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享