[VulnDiscuss] Dangerous permissions in unitedlinux
Knud Erik Højgaard <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <004e01c2fd2f$d123f4c0$24029dd9@tuborg> |
Attached document explains all. Rant: People using a product called 'antigen' should be shot, stabbed, and shot again. Today, more than a month after posting DSR-toppler.pl and sircd.sh, I _still_ get 5-8 emails a day saying that 'a virus have been found and quarantined'. Oh please, get a grip. And please oh please stop sending email from invalid addresses, I can't even mail you back and tell you what I think of your AV solution. -- Knud Erik Højgaard
DSR-unitedlinux.txt
(text/plain, 773 B)
I. BACKGROUND According to the vendor "UnitedLinux addresses enterprise customers' needs for a high quality, low cost, standards-based Linux environment that enables the widespread adoption of Linux." II. DESCRIPTION The folders below /usr/src/packages/ ships with the following permissions: drwxrwxrwt, which makes it writeable by all users. III. ANALYSIS This makes way for planting of rogue source, ultimately leading to a full system compromise. IV. DETECTION UnitedLinux 1.0 (i586) beta3 is found to be vulnerable. V. WORKAROUND Change the permissions on /usr/src/packages/* and below to something more suitable. VI. VENDOR FIX unknown VII. CVE INFORMATION unknown VIII. DISCLOSURE TIMELINE unknown IX. CREDIT Knud Erik Højgaard/kokanin[a]dtors.net