Inert Ramblings

Everything worth saying has already been said…

Inert Ramblings
August 25, 1996 by Sciri

Symlink Vulnerability in TIN

Improper handling of /tmp symlinks.

                                                       Monday, August 26, 1996
                                                                 The Litterbox
                                          Sean B. Hamor <hamors@litterbox.org>
                                                                           TIN

Note:

  I'm not sure whether or not information this has been previously released.
  I found this earlier this evening while poking around, and apologize if
  I've just found an old bug.

  I verified the existence of this bug in TIN 1.2PL2 UNIX.

Synopsis:

  A problem exists in TIN where the .tin_log file in /tmp/ is created mode
  666.  Although this file is usually created the first time a user runs TIN
  and doesn't get deleted, a problem develops if root or the owner of that
  file deletes it while cleaning up /tmp/.

  If /tmp/.tin_log is deleted, a symbolic link may now be put in its place
  and be used to create/modify/delete files the victim has write access to.

Exploit:

  hamors (3 21:00) litterbox:/tmp> ln -s ~root/.rhosts /tmp/.tin_log

Verification:

  This vulnerability has been tested on Linux Slackware 3.0 (1.2.13) with
  TIN 1.2PL2.

EOF

Posted in Gnus. RSS 2.0 feed.
« How to configure UNIX PINE for use with PGP
Sensory perception… »

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

*

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Categories

Archives

Blogroll

  • Development Blog
  • Documentation
  • Plugins
  • Suggest Ideas
  • Support Forum
  • Themes
  • WordPress Planet

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Pages

  • About Inert Ramblings

All content © 2012 by Inert Ramblings. WordPress Themes by Graph Paper Press