CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#369427

Format string vulnerability in libutil pw_error(3) function

Overview

There is an input validation vulnerability in the OpenBSD libutil system library that allows local users to gain superuser access via the chpass utility.

I. Description

On June 30, 2000, the OpenBSD development team repaired an input validation vulnerability in the pw_error function of the OpenBSD 2.7 libutil library.

It was later discovered that when this function is called by the setuid program /usr/bin/chpass on unpatched systems, it is possible for users to obtain superuser access.

II. Impact

Attackers with an account on affected systems can obtain superuser access via the chpass utility.

III. Solution

Apply a patch from your vendor.

See the vendors section of this document for further information from your vendor.

The CERT/CC recommends that vulnerable users protect their systems by removing the SUID bit on chpass.

Systems Affected

VendorStatusDate Updated
AppleNot Vulnerable27-Oct-2000
BSDINot Vulnerable27-Oct-2000
Compaq Computer CorporationNot Vulnerable27-Oct-2000
FreeBSDVulnerable31-Oct-2000
FujitsuNot Vulnerable20-Jan-2001
Hewlett PackardNot Vulnerable3-Jan-2001
NetBSDVulnerable27-Oct-2000
OpenBSDVulnerable17-Nov-2000

References


http://www.securityfocus.com/bid/1744
http://www.openbsd.org/errata.html (025)
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/025_pw_error.patch

Credit

This document was written by Jeffrey P. Lanza.

Other Information

Date Public10/03/2000
Date First Published11/07/2000 05:18:58 PM
Date Last Updated03/29/2001
CERT Advisory 
CVE NameCAN-2000-0993
Metric11.16
Document Revision9

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2000 Carnegie Mellon University