CVE-2000-0697
CVSS10.0
发布时间 :2000-10-20 00:00:00
修订时间 :2008-09-24 00:07:12
NMCOES    

[原文]The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.


[CNNVD]Solaris AnswerBook2远程命令执行漏洞(CNNVD-200010-135)

        Solaris AnswerBook2中dwhttpd web服务器的管理界面存在漏洞。界面用户可以借助shell元字符来远程执行命令。

- CVSS (基础分值)

CVSS分值: 10 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: COMPLETE [系统完整性可被完全破坏]
可用性影响: COMPLETE [可能导致系统完全宕机]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:sun:solaris_answerbook2:1.4.2Sun Solaris AnswerBook2 1.4.2
cpe:/a:sun:solaris_answerbook2:1.4Sun Solaris AnswerBook2 1.4
cpe:/a:sun:solaris_answerbook2:1.3
cpe:/a:sun:solaris_answerbook2:1.4.1

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0697
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2000-0697
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200010-135
(官方数据源) CNNVD

- 其它链接及资源

http://www.securityfocus.com/bid/1556
(VENDOR_ADVISORY)  BID  1556
http://archives.neohapsis.com/archives/sun/2000-q3/0001.html
(VENDOR_ADVISORY)  SUN  00196
http://www.s21sec.com/en/avisos/s21sec-004-en.txt
(UNKNOWN)  MISC  http://www.s21sec.com/en/avisos/s21sec-004-en.txt
http://www.iss.net/security_center/static/5058.php
(UNKNOWN)  XF  solaris-answerbook2-remote-execution(5058)
http://seclists.org/bugtraq/2000/Aug/0105.html
(UNKNOWN)  BUGTRAQ  20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server

- 漏洞信息

Solaris AnswerBook2远程命令执行漏洞
危急 未知
2000-10-20 00:00:00 2005-10-20 00:00:00
远程  
        Solaris AnswerBook2中dwhttpd web服务器的管理界面存在漏洞。界面用户可以借助shell元字符来远程执行命令。

- 公告与补丁

        The vendor has released the following patches to address this issue:
        Sun AnswerBook2 1.3
        
        Sun AnswerBook2 1.4
        
        Sun AnswerBook2 1.4.1
        
        Sun AnswerBook2 1.4.2
        

- 漏洞信息 (20146)

Solaris AnswerBook2 Remote Command Execution Vulnerability (EDBID:20146)
solaris remote
2000-08-07 Verified
0 Lluis Mora
N/A [点击下载]
source: http://www.securityfocus.com/bid/1556/info

A vulnerability exists in version 1.4.2 and prior of the AnswerBook2 server from Sun. It is possible for remote users who have administrative access to execute arbitrary commands on the machine running AnswerBook2. These commands will be executed with the privileges of user 'daemon'

One of the options you have while administering the AB2 is to rotate the
access and error logs. The server allows you to specify the target file 
where the logs will be rotated to. You can use ../../../../../this/file to
create and overwrite files outside the web server document root directory.
Further investigation showed that the server performs the following command
to rotate the server logs:

sh -c "cp /var/log/ab2/logs/original_log
/var/log/ab2/logs/USER_PROVIDED_TARGET" 

So an attacker could specify a destination log like "x ; uname -a" that will
translate to:

sh -c "cp /var/log/ab2/logs/original_log /var/log/abs/logs/x ; uname -a"		

- 漏洞信息

8680
Sun AnswerBook2 Web Server dwhttpd shell metacharacters Remote Command Execution
Remote / Network Access Input Manipulation
Loss of Integrity Patch / RCS
Exploit Public Third-party Verified

- 漏洞描述

Sun Solaris Answerbook2 shipped with the dwhttpd package contains a flaw that may allow a malicious user to run commands remotely. The issue is due to the insufficient input validation for cgi scripts in the admininstration interface of Answerbook2. By sending a specially crafted URL request with shell metacharacters to port 8888, a remote attacker can run the commands with web user privileges, resulting in a loss of integrity.

- 时间线

2000-08-07 Unknow
2000-08-07 Unknow

- 解决方案

Currently, there are no known workarounds or upgrades to correct this issue. However, Sun Microsystems has released a patch to address this vulnerability.

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

Solaris AnswerBook2 Remote Command Execution Vulnerability
Unknown 1556
Yes No
2000-08-07 12:00:00 2009-07-11 02:56:00
This vulnerability was reported to the Bugtraq mailing list on August 7, 2000 by "Lluis Mora" <llmora@s21sec.com>

- 受影响的程序版本

Sun AnswerBook2 1.4.2
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- Sun Solaris 2.6
- Sun Solaris 2.6
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.3
- Sun Solaris 2.3
- Sun Solaris 2.3
Sun AnswerBook2 1.4.1
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 8_x86
- Sun Solaris 8_x86
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.3
- Sun Solaris 2.3
- Sun Solaris 2.3
Sun AnswerBook2 1.4
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- Sun Solaris 2.6
- Sun Solaris 2.6
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.3
- Sun Solaris 2.3
- Sun Solaris 2.3
Sun AnswerBook2 1.3
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _x86
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1 _ppc
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- Sun Solaris 2.6
- Sun Solaris 2.6
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5_x86
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.5
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4_x86
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.4
- Sun Solaris 2.3
- Sun Solaris 2.3
- Sun Solaris 2.3

- 漏洞讨论

A vulnerability exists in version 1.4.2 and prior of the AnswerBook2 server from Sun. It is possible for remote users who have administrative access to execute arbitrary commands on the machine running AnswerBook2. These commands will be executed with the privileges of user 'daemon'

- 漏洞利用

From the Bugtraq post:

One of the options you have while administering the AB2 is to rotate the
access and error logs. The server allows you to specify the target file
where the logs will be rotated to. You can use ../../../../../this/file to
create and overwrite files outside the web server document root directory.
Further investigation showed that the server performs the following command
to rotate the server logs:

sh -c "cp /var/log/ab2/logs/original_log
/var/log/ab2/logs/USER_PROVIDED_TARGET"

So an attacker could specify a destination log like "x ; uname -a" that will
translate to:

sh -c "cp /var/log/ab2/logs/original_log /var/log/abs/logs/x ; uname -a"

- 解决方案

The vendor has released the following patches to address this issue:


Sun AnswerBook2 1.3

Sun AnswerBook2 1.4

Sun AnswerBook2 1.4.1

Sun AnswerBook2 1.4.2

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站