oss-sec mailing list archives
CVE request: tss <= 0.8.1-3: arbitary file reading
From: Steve Kemp <steve () steve org uk>
Date: Sat, 12 Apr 2008 20:32:36 +0100
Due to a lack of permissions checking, or privilege reduction
the setuid(0) binary tss allows local users to read arbitrary files
upon the local system.
Sample "exploit" is:
skx@gold:~$ tss -a /etc/shadow
This opens up a console-based screen-saver displaying the animated
contents of the shadow-file.
Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475747
Steve
--
Debian GNU/Linux System Administration
http://www.debian-administration.org/
Current thread:
- CVE request: tss <= 0.8.1-3: arbitary file reading Steve Kemp (Apr 12)
- Re: CVE request: tss <= 0.8.1-3: arbitary file reading Nico Golde (Apr 17)
- Re: CVE request: tss <= 0.8.1-3: arbitary file reading Steven M. Christey (Apr 17)
- Re: CVE request: tss <= 0.8.1-3: arbitary file reading Nico Golde (Apr 17)
