oss-sec mailing list archives

CVE request: tss <= 0.8.1-3: arbitary file reading


From: Steve Kemp <steve () steve org uk>
Date: Sat, 12 Apr 2008 20:32:36 +0100

  Due to a lack of permissions checking, or privilege reduction
 the setuid(0) binary tss allows local users to read arbitrary files
 upon the local system.

  Sample "exploit" is:

              skx@gold:~$ tss -a /etc/shadow

  This opens up a console-based screen-saver displaying the animated
 contents of the shadow-file.

  Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475747

Steve
-- 
Debian GNU/Linux System Administration
http://www.debian-administration.org/



Current thread: