Download Firefox: WindowsMac OS X
logo       
Google Custom Search
    AddThis Social Bookmark Button

Previously audited program with new holes: msg#00016

Subject: Previously audited program with new holes
  One of the previously examined programs which had a
 hole was crawl.  That involved the use of environmental
 variables.

  The new hole is the execution of commands without
 qualifying their paths, and without dropping privileges.

  The new DSA covers it:

        http://www.debian.org/security/2006/dsa-949

  An interesting problem to fix.  The program saves
 games beneath /var/games/crawl/ so it needs gid(games)
 privileges to write there...

  Exploit attached, along with the discussion.
-- 
Steve
-- 
# The Debian Security Audit Project.
http://www.debian.org/security/audit

Attachment: crawl.txt
Description: Text document

Attachment: crawl.sh
Description: Bourne shell script

Attachment: signature.asc
Description: Digital signature

_______________________________________________
Debian-audit mailing list
Debian-audit@xxxxxxxxxxxxx
http://shellcode.org/mailman/listinfo/debian-audit
<Prev in Thread] Current Thread [Next in Thread>