|
|
|
Vulnerability Note VU#396272
mgetty creates temporary files insecurely
Overviewmgetty, a replacement for getty designed to support modem and fax use, creates files of a predictable name in a world-writable directory without checking for the prior existence or ownership of the file. Using a symbolic link attack, an intruder might cause the overwrite of arbitrary files on the system, but the risk of elevated privileges is low.
I. Descriptionmgetty uses the faxrunq service to process faxes. This involves use of the world-writable /var/spool/fax/outgoing/ directory to store temporary files. These temporary files are created without checking for prior existence or ownership of the files. II. ImpactBy creating a symbolic link named '.last_run' and pointing towards any existing file, an attacker can cause mgetty to overwrite the file. Since the attacker cannot control the content of the overwritten file, the risk of exploiting this for elevated privileges is low.III. SolutionApply vendor patches; see the Systems Affected section below.
Disable the faxrunq service.
Systems Affected
| Vendor | Status | Date Updated |
| Apple | Not Vulnerable | 20-Sep-2001 |
| BSDI | Unknown | 20-Sep-2001 |
| Caldera | Vulnerable | 13-Sep-2001 |
| Cray | Not Vulnerable | 27-Sep-2001 |
| Cray | Unknown | 20-Sep-2001 |
| Data General | Unknown | 20-Sep-2001 |
| Debian | Vulnerable | 13-Sep-2001 |
| DEC | Unknown | 20-Sep-2001 |
| FreeBSD | Vulnerable | 13-Sep-2001 |
| Fujitsu | Unknown | 20-Sep-2001 |
| HP | Not Vulnerable | 20-Sep-2001 |
| IBM | Not Vulnerable | 20-Sep-2001 |
| Immunix | Vulnerable | 13-Sep-2001 |
| MandrakeSoft | Vulnerable | 13-Sep-2001 |
| NEC | Unknown | 20-Sep-2001 |
| NetBSD | Not Vulnerable | 8-Nov-2001 |
| NeXT | Unknown | 20-Sep-2001 |
| OpenBSD | Not Vulnerable | 20-Sep-2001 |
| RedHat | Vulnerable | 20-Sep-2001 |
| SCO | Not Vulnerable | 20-Sep-2001 |
| Sequent | Unknown | 20-Sep-2001 |
| SGI | Unknown | 20-Sep-2001 |
| Sony | Unknown | 20-Sep-2001 |
| Sun | Unknown | 20-Sep-2001 |
| Unisys | Unknown | 20-Sep-2001 |
References
http://www.securityfocus.com/bid/2187
http://www.caldera.com/support/security/advisories/CSSA-2001-002.0.txt
http://www.linuxsecurity.com/advisories/caldera_advisory-1059.html
http://lists.debian.org/debian-security-announce/debian-security-announce-2001/msg00000.html
http://www.linuxsecurity.com/advisories/debian_advisory-1184.html
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:71.mgetty.asc
http://www.linuxsecurity.com/advisories/freebsd_advisory-894.html
http://www.redhat.com/support/errata/RHSA-2001-050.html
http://www.linuxsecurity.com/advisories/redhat_advisory-1321.html
http://www.linux-mandrake.com/en/updates/2001/MDKSA-2001-009.php3?dis=6.1
http://www.linuxsecurity.com/advisories/other_advisory-1034.html
Credit
This vulnerability was first identified by Greg Kroah-Hartman of Immunix.
This document was last changed by Tim Shimeall.
Other Information
| Date Public | 01/10/2001 |
| Date First Published | 10/01/2001 01:07:23 PM |
| Date Last Updated | 11/08/2001 |
| CERT Advisory | |
| CVE Name | CAN-2001-0141 |
| Metric | 1.13 |
| Document Revision | 17 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |