|
[UNIX] log4sh Insecure Temporary Files Creation Vulnerability: msg#00010security.securiteam
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - log4sh Insecure Temporary Files Creation Vulnerability ------------------------------------------------------------------------ SUMMARY " <http://forestent.com/products/log4sh/> Log4sh runs along the same lines as the other excellent logging services from the Apache Software Foundation. It adds to that list the ability to integrate powerful logging capabilities into a shell script." log4sh creates temporally files in an insecure way allowing local attackers to gain elevated privileges. DETAILS Vulnerable Systems: * log4sh versions 1.2.5 and prior The vulnerability is caused due to temporary files being created insecurely. This can be exploited via a symlink attack, and in turn create and/or overwrite arbitrary files with the privileges of the user running the affected script. Vulnerable code: 356 log4sh_readProperties() 357 { 358 _file=$1 359 360 _tmpFile="/tmp/log4sh.$$" 361 grep "^log4sh\." $_file >$_tmpFile CVE Information: <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1915> CAN-2005-1915 Disclosure Timeline: 26.05.05 - Discovered 09.06.05 - Vendor notified 27.06.05 - No response, Vendor Sec report (vendor-sec@xxxxxx) 04.07.05 - Disclosure ADDITIONAL INFORMATION The original article can be found at: <http://www.zataz.net/adviso/log4sh-06092005.txt> http://www.zataz.net/adviso/log4sh-06092005.txt Gentoo Bugs Reports: <http://bugs.gentoo.org/show_bug.cgi?id=94069 > http://bugs.gentoo.org/show_bug.cgi?id=94069 ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | [EXPL] TCP Chat(TCPX) DoS (Exploit): 00010, SecuriTeam |
|---|---|
| Next by Date: | [UNIX] Nokia Affix btftp Remote Buffer Overflow Exploit: 00010, SecuriTeam |
| Previous by Thread: | [EXPL] TCP Chat(TCPX) DoS (Exploit)i: 00010, SecuriTeam |
| Next by Thread: | [UNIX] Nokia Affix btftp Remote Buffer Overflow Exploit: 00010, SecuriTeam |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |