Caldera OpenServer SCOAdmin符号链接漏洞

Caldera OpenServer SCOAdmin符号链接漏洞

漏洞ID 1106756 漏洞类型 未知
发布时间 2002-05-29 更新时间 2005-05-02
图片[1]-Caldera OpenServer SCOAdmin符号链接漏洞-安全小百科CVE编号 CVE-2002-0887
图片[2]-Caldera OpenServer SCOAdmin符号链接漏洞-安全小百科CNNVD-ID CNNVD-200210-131
漏洞平台 SCO CVSS评分 2.1
|漏洞来源
https://www.exploit-db.com/exploits/21489
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200210-131
|漏洞详情
OpenServer是一款由Caldera维护的商业性质Unix类型操作系统。OpenServer中的socadmin工具运行时存在漏洞,可导致本地攻击者进行符号链接攻击。socadmin工具在运行的时候会建立临时文件,其中临时文件的名称可以猜测,并程序对临时文件是否存在没有很好的检查,可导致本地攻击者使用符号链接指向任意系统文件,当socadmin运行时,覆盖符号连接指向的程序,破坏程序导致系统产生拒绝服务。
|漏洞EXP
source: http://www.securityfocus.com/bid/4875/info

A vulnerability has been reported in the scoadmin utility that may allow a local attacker to overwrite any file. The vulnerability is due to the predictable naming of temporary files used by scoadmin. When writing to temporary files, there are no checks to ensure that it does not already exist. Symbolic links will also be followed. This behaviour may be exploited by local attackers to corrupt arbitrary files.

ln -s /etc/passwd /tmp/tclerror.1195.log

If the process ID of the SCOadmin process is 1195, /etc/passwd will be overwritten.
|参考资料

来源:BID
名称:4875
链接:http://www.securityfocus.com/bid/4875
来源:XF
名称:openserver-scoadmin-symlink(9210)
链接:http://www.iss.net/security_center/static/9210.php
来源:CALDERA
名称:CSSA-2002-SCO.22
链接:ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.22/CSSA-2002-SCO.22.txt
来源:BUGTRAQ
名称:20010522[SRT2001-10]-scoadmin/tmpissues
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=99057164129869&w;=2

相关推荐: @EZmeeting EZmeeting EZmeeting 缓冲区溢出漏洞

@EZmeeting EZmeeting EZmeeting 缓冲区溢出漏洞 漏洞ID 1107596 漏洞类型 缓冲区溢出 发布时间 2003-12-15 更新时间 2003-12-31 CVE编号 CVE-2003-1339 CNNVD-ID CNNVD-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享