HP SNMPD文件许可漏洞

HP SNMPD文件许可漏洞

漏洞ID 1105878 漏洞类型 访问验证错误
发布时间 2000-06-07 更新时间 2005-05-02
图片[1]-HP SNMPD文件许可漏洞-安全小百科CVE编号 CVE-2000-0515
图片[2]-HP SNMPD文件许可漏洞-安全小百科CNNVD-ID CNNVD-200006-032
漏洞平台 HP-UX CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/20002
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200006-032
|漏洞详情
HP-UX11.0版本中SNMP守护程序(snmpd)的snmpd.conf配置文件存在漏洞。本地用户利用此漏洞可以修改SNMP文件或提升特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/1327/info

A vulnerability exists in the snmpd included with HPUX 11, from Hewlett Packard. The configuration file for the snmpd is world writable. This could allow any user on the system to view and/or alter the settings of the snmp daemon. This in turn could be used to alter the configuration of the system, including, but not limited to, routing, addressing, arp caches, the status of connections, and so on. It is also possible this could be used to elevate access levels.

Another vulnerability exists which allows users to redirect the logging location of snmpd to an alternate location, using symbolic links. This file is in a mode 777 directory, so any user can remove a file that already exists. Used in conjunction with the ability to alter configuration, this may also help leverage root access. This file is created at boot time, and while /tmp is cleared of its contents, there may be a potential window where a user can create a symbolic link prior to its creation, and directly use this to elevate privileges. 

edit /etc/SnmpAgent.d/snmpd.conf. It is world writable.
|参考资料

来源:XF
名称:hpux-snmp-daemon
链接:http://xforce.iss.net/static/4643.php
来源:BUGTRAQ
名称:20000608Re:HP-UXSNMPdaemonvulnerability
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg;[email protected]
来源:BUGTRAQ
名称:20000607[Hackerslabbug_paper]HP-UXSNMPdaemonvulnerability
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg;[email protected]
来源:BID
名称:1327
链接:http://www.securityfocus.com/bid/1327

相关推荐: Telnet listener获取访问权限漏洞

Telnet listener获取访问权限漏洞 漏洞ID 1200737 漏洞类型 未知 发布时间 2004-12-31 更新时间 2004-12-31 CVE编号 CVE-2004-2314 CNNVD-ID CNNVD-200412-319 漏洞平台 N/…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享