BugTraq
Solaris priocntl exploit Nov 27 2002 03:00AM
ÝþÒãÁ? (kk_qq 263 net) (3 replies)
Re: Solaris priocntl exploit - Sol8 patches available Dec 27 2002 01:15PM
Scott Howard (scott doc net au)
Re: Solaris priocntl exploit Dec 02 2002 04:45PM
Jay Beale (jay bastille-linux org) (1 replies)
> but unfortunately, priocntl() never check '../' in pc_clname arg
> we can use '../../../tmp/module' to make priocntl() load a module from anywhere

You've got to love when this kind of classic mistake happens in a system call!

I latched onto this one simply because it's the same poor input
validation/permissions check that happens in my favorite old privilege escalator,
userhelper. ( http://online.securityfocus.com/bid/913 )

This always gets classified as bad input validation. Is the right answer really
to check for ../ 's or to canonicalize the filename argument and check ownerships
and permissions on the file and parent directories?

- Jay

[ reply ]
Re: Solaris priocntl exploit Dec 23 2002 10:58AM
Pavel Kankovsky (peak argo troja mff cuni cz)
Re: Solaris priocntl exploit Nov 27 2002 08:56PM
Casper Dik (Casper Dik Sun COM)


 

Privacy Statement
Copyright 2010, SecurityFocus