|
|
|
![]() |
Vulnerability Note VU#35842man 'makewhatis' insecurely uses /tmpOverviewThe 'makewhatis' script in the Linux man package allows local users to overwrite files via a symlink attack.I. DescriptionThe 'makewhatis' program is a Bourne shell script that ships with many Linux distributions in the 'man' package of programs. The 'makewhatis' script creates files in the /tmp directory with predictable names. By using various symlink attacks, it is possible for local users to exploit this predictability to create or modify arbitrary files and gain elevated privilege. In addition, the 'makewhatis' script is run daily to rebuild the database used by the 'whatis' command. Local users may be able to read any system file by forcing a copy of it into the 'whatis' database.The man package version 1.5e and higher is vulnerable to this flaw.
Referenceshttp://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0566 Thanks to Red Hat for the information contained in their security advisory. This document was written by Andrew P. Moore.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||