CVE-2005-0953
CVSS3.7
发布时间 :2005-05-02 00:00:00
修订时间 :2016-10-17 23:15:57
NMCOPS    

[原文]Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.


[CNNVD]BZip2 TOCTOUd文件权限漏洞(CNNVD-200505-022)

        bzip2是一款文件压缩工具,支持Unix和Windows平台。
        如果恶意的本地用户可以写访问目录,而目标用户在该目录中使用bzip2压缩或解压文件的话,则攻击者就可以利用TOCTOU漏洞,更改任何属于目标用户文件的权限。在解压时bzip2将压缩bzip2文件的权限拷贝到解压的文件。但是,在写入解压的文件和更改文件权限之间有个时间差,恶意用户可以利用这个时间差删除解压的文件,并用用户其他文件的硬链接替换它,这样bzip2就可以将硬链接文件的权限改为与bzip2文件相同的权限。

- CVSS (基础分值)

CVSS分值: 3.7 [轻微(LOW)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: HIGH [漏洞利用存在特定的访问条件]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:bzip:bzip2:0.9
cpe:/a:bzip:bzip2:1.0.2
cpe:/a:bzip:bzip2:1.0.1
cpe:/a:bzip:bzip2:1.0
cpe:/a:bzip:bzip2:0.9.5_a
cpe:/a:bzip:bzip2:0.9_a
cpe:/a:bzip:bzip2:0.9.5_b
cpe:/a:bzip:bzip2:0.9.5_c
cpe:/a:bzip:bzip2:0.9_c
cpe:/a:bzip:bzip2:0.9.5_d
cpe:/a:bzip:bzip2:0.9_b

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:1154bzip2 Arbitrary File Permission Modification Vulnerability
oval:org.mitre.oval:def:10902Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while...
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0953
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-0953
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200505-022
(官方数据源) CNNVD

- 其它链接及资源

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc
(UNKNOWN)  NETBSD  NetBSD-SA2008-004
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc
(UNKNOWN)  SGI  20060301-01-U
http://docs.info.apple.com/article.html?artnum=307041
(UNKNOWN)  CONFIRM  http://docs.info.apple.com/article.html?artnum=307041
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
(UNKNOWN)  APPLE  APPLE-SA-2007-11-14
http://marc.info/?l=bugtraq&m=111229375217633&w=2
(UNKNOWN)  BUGTRAQ  20050330 bzip2 TOCTOU file-permissions vulnerability
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103118-1
(UNKNOWN)  SUNALERT  103118
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200191-1
(UNKNOWN)  SUNALERT  200191
http://www.debian.org/security/2005/dsa-730
(VENDOR_ADVISORY)  DEBIAN  DSA-730
http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html
(UNKNOWN)  FEDORA  FLSA:158801
http://www.mandriva.com/security/advisories?name=MDKSA-2006:026
(UNKNOWN)  MANDRIVA  MDKSA-2006:026
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html
(UNKNOWN)  OPENPKG  OpenPKG-SA-2007.002
http://www.redhat.com/support/errata/RHSA-2005-474.html
(UNKNOWN)  REDHAT  RHSA-2005:474
http://www.securityfocus.com/archive/1/archive/1/456430/30/8730/threaded
(UNKNOWN)  BUGTRAQ  20070109 rPSA-2007-0004-1 bzip2
http://www.securityfocus.com/bid/12954
(UNKNOWN)  BID  12954
http://www.securityfocus.com/bid/26444
(UNKNOWN)  BID  26444
http://www.us-cert.gov/cas/techalerts/TA07-319A.html
(UNKNOWN)  CERT  TA07-319A
http://www.vupen.com/english/advisories/2007/3525
(UNKNOWN)  VUPEN  ADV-2007-3525
http://www.vupen.com/english/advisories/2007/3868
(UNKNOWN)  VUPEN  ADV-2007-3868
http://xforce.iss.net/xforce/xfdb/19926
(UNKNOWN)  XF  bzip2-toctou-symlink(19926)

- 漏洞信息

BZip2 TOCTOUd文件权限漏洞
低危 竞争条件
2005-05-02 00:00:00 2005-10-20 00:00:00
本地  
        bzip2是一款文件压缩工具,支持Unix和Windows平台。
        如果恶意的本地用户可以写访问目录,而目标用户在该目录中使用bzip2压缩或解压文件的话,则攻击者就可以利用TOCTOU漏洞,更改任何属于目标用户文件的权限。在解压时bzip2将压缩bzip2文件的权限拷贝到解压的文件。但是,在写入解压的文件和更改文件权限之间有个时间差,恶意用户可以利用这个时间差删除解压的文件,并用用户其他文件的硬链接替换它,这样bzip2就可以将硬链接文件的权限改为与bzip2文件相同的权限。

- 公告与补丁

        目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
        http://sources.redhat.com/bzip2/index.html

- 漏洞信息 (F53505)

OpenPKG Security Advisory 2007.2 (PacketStormID:F53505)
2007-01-13 00:00:00
OpenPKG Foundation  openpkg.com
advisory
CVE-2005-0953,CVE-2005-0758
[点击下载]

OpenPKG Security Advisory - Together with two portability and stability issues, two older security issues were fixed in the compression tool BZip2, versions up to and including 1.0.3.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

____________________________________________________________________________

Publisher Name:          OpenPKG GmbH
Publisher Home:          http://openpkg.com/

Advisory Id (public):    OpenPKG-SA-2007.002
Advisory Type:           OpenPKG Security Advisory (SA)
Advisory Directory:      http://openpkg.com/go/OpenPKG-SA
Advisory Document:       http://openpkg.com/go/OpenPKG-SA-2007.002
Advisory Published:      2007-01-05 21:58 UTC

Issue Id (internal):     OpenPKG-SI-20070105.01
Issue First Created:     2007-01-05
Issue Last Modified:     2007-01-05
Issue Revision:          04
____________________________________________________________________________

Subject Name:            bzip2
Subject Summary:         Compression Tool
Subject Home:            http://www.bzip.org/
Subject Versions:        * <= 1.0.3

Vulnerability Id:        CVE-2005-0953, CVE-2005-0758
Vulnerability Scope:     global (not OpenPKG specific)

Attack Feasibility:      run-time
Attack Vector:           local system
Attack Impact:           manipulation of data, arbitrary code execution

Description:
    Together with two portability and stability issues, two older
    security issues were fixed in the compression tool BZip2 [0], versions
    up to and including 1.0.3.
    
    The first issue is a race condition which allows local users to
    modify permissions of arbitrary files via a hard link attack on a
    file while it is being decompressed, whose permissions are changed
    by bzip2 after the decompression is complete.
    
    The second issue affects the script bzgrep(1). It does not properly
    sanitize arguments, which allows local users to execute arbitrary
    commands via filenames that are injected into a sed(1) script.

References:
    [0] http://www.bzip.org/
____________________________________________________________________________

Primary Package Name:    bzip2
Primary Package Home:    http://openpkg.org/go/package/bzip2

Corrected Distribution:  Corrected Branch: Corrected Package:
OpenPKG Enterprise       E1.0-SOLID        bzip2-1.0.3-E1.0.1
OpenPKG Enterprise       E1.0-SOLID        openpkg-E1.0.2-E1.0.2
OpenPKG Community        2-STABLE-20061018 bzip2-1.0.4-2.20070105
OpenPKG Community        2-STABLE-20061018 openpkg-2.20070105-2.20070105
OpenPKG Community        2-STABLE          bzip2-1.0.4-2.20070105
OpenPKG Community        2-STABLE          openpkg-2.20070105-2.20070105
OpenPKG Community        CURRENT           bzip2-1.0.4-20070105
OpenPKG Community        CURRENT           openpkg-20070105-20070105
____________________________________________________________________________

For security reasons, this document was digitally signed with the
OpenPGP public key of the OpenPKG GmbH (public key id 61B7AE34)
which you can download from http://openpkg.com/openpkg.com.pgp
or retrieve from the OpenPGP keyserver at hkp://pgp.openpkg.org/.
Follow the instructions at http://openpkg.com/security/signatures/
for more details on how to verify the integrity of this document.
____________________________________________________________________________

-----BEGIN PGP SIGNATURE-----
Comment: OpenPKG GmbH <http://openpkg.com/>

iD8DBQFFnrwRZwQuyWG3rjQRAgkdAJ9YBx7auj7ursOTj5M/78Kq3SlGlACfc0aV
2IRFnTk4CCJwa9FPgv1z7c0=
=Iq2w
-----END PGP SIGNATURE-----
    

- 漏洞信息

15237
bzip2 Race Condition Arbitrary File Permission Modification
Local Access Required Input Manipulation
Loss of Integrity Patch / RCS
Exploit Unknown Vendor Verified

- 漏洞描述

bzip2 contains a flaw that may allow a local attacker to change permissions of arbitrary files on the system. The issue is triggered via a hard link attack on a file while it is being decompressed. This flaw may allow a local attacker to modify arbitrary permissions of files.

- 时间线

2005-03-31 Unknow
Unknow 2005-06-16

- 解决方案

Multiple Linux distributions have released upgrades to address this vulnerability. Check the vendor advisory, changelog, or solution in the references section for details.

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

bzip2 chmod File Permission Modification Race Condition Weakness
Race Condition Error 12954
No Yes
2005-03-31 12:00:00 2008-07-02 07:30:00
Discovery of this weakness is credited to Imran Ghory <imranghory@gmail.com>.

- 受影响的程序版本

Ubuntu Ubuntu Linux 5.0 4 powerpc
Ubuntu Ubuntu Linux 5.0 4 i386
Ubuntu Ubuntu Linux 5.0 4 amd64
Ubuntu Ubuntu Linux 4.1 ppc
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ia32
Turbolinux Turbolinux Workstation 8.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Server 10.0
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Desktop 10.0
Turbolinux Home
Turbolinux Appliance Server 1.0 Workgroup Edition
Turbolinux Appliance Server 1.0 Hosting Edition
Trustix Secure Linux 3.0
Trustix Secure Linux 2.2
Trustix Operating System Enterprise Server 2.0
Sun Solaris 9_x86
Sun Solaris 9
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 10.0_x86
Sun Solaris 10.0
SGI ProPack 3.0 SP6
SGI ProPack 3.0 SP5
rPath rPath Linux 1
RedHat Linux 9.0 i386
RedHat Linux 7.3 i686
RedHat Linux 7.3 i386
RedHat Linux 7.3
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux WS 2.1 IA64
RedHat Enterprise Linux WS 2.1
RedHat Enterprise Linux ES 4
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux ES 2.1 IA64
RedHat Enterprise Linux ES 2.1
RedHat Desktop 4.0
RedHat Desktop 3.0
RedHat Advanced Workstation for the Itanium Processor 2.1 IA64
RedHat Advanced Workstation for the Itanium Processor 2.1
Red Hat Fedora Core2
Red Hat Fedora Core1
Red Hat Enterprise Linux AS 4
Red Hat Enterprise Linux AS 3
Red Hat Enterprise Linux AS 2.1 IA64
Red Hat Enterprise Linux AS 2.1
OpenPKG OpenPKG 2.3
OpenPKG OpenPKG 2.2
NetBSD NetBSD Current
NetBSD NetBSD 4.0
NetBSD NetBSD 3.1
Navision Financials Server 3.0
Mandriva Linux Mandrake 2006.0 x86_64
Mandriva Linux Mandrake 2006.0
Mandriva Linux Mandrake 10.2 x86_64
Mandriva Linux Mandrake 10.2
Mandriva Linux Mandrake 10.1 x86_64
Mandriva Linux Mandrake 10.1
Mandriva Linux Mandrake 10.0 AMD64
Mandriva Linux Mandrake 10.0
MandrakeSoft Multi Network Firewall 2.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 2.1 x86_64
MandrakeSoft Corporate Server 2.1
FreeBSD FreeBSD 5.4 -RELENG
FreeBSD FreeBSD 5.4 -RELEASE
FreeBSD FreeBSD 5.4 -PRERELEASE
FreeBSD FreeBSD 5.3 -STABLE
FreeBSD FreeBSD 5.3 -RELENG
FreeBSD FreeBSD 5.3 -RELEASE
FreeBSD FreeBSD 5.3
FreeBSD FreeBSD 5.2.1 -RELEASE
FreeBSD FreeBSD 5.2 -RELENG
FreeBSD FreeBSD 5.2 -RELEASE
FreeBSD FreeBSD 5.2
FreeBSD FreeBSD 5.1 -RELENG
FreeBSD FreeBSD 5.1 -RELEASE/Alpha
FreeBSD FreeBSD 5.1 -RELEASE-p5
FreeBSD FreeBSD 5.1 -RELEASE
FreeBSD FreeBSD 5.1
FreeBSD FreeBSD 5.0 -RELENG
FreeBSD FreeBSD 5.0 -RELEASE-p14
FreeBSD FreeBSD 5.0 alpha
FreeBSD FreeBSD 5.0
FreeBSD FreeBSD 4.11 -STABLE
FreeBSD FreeBSD 4.11 -RELENG
FreeBSD FreeBSD 4.11 -RELEASE-p3
FreeBSD FreeBSD 4.10 -RELENG
FreeBSD FreeBSD 4.10 -RELEASE-p8
FreeBSD FreeBSD 4.10 -RELEASE
FreeBSD FreeBSD 4.10
FreeBSD FreeBSD 4.9 -RELENG
FreeBSD FreeBSD 4.9 -PRERELEASE
FreeBSD FreeBSD 4.9
FreeBSD FreeBSD 4.8 -RELENG
FreeBSD FreeBSD 4.8 -RELEASE-p7
FreeBSD FreeBSD 4.8 -PRERELEASE
FreeBSD FreeBSD 4.8
FreeBSD FreeBSD 4.7 -STABLE
FreeBSD FreeBSD 4.7 -RELENG
FreeBSD FreeBSD 4.7 -RELEASE-p17
FreeBSD FreeBSD 4.7 -RELEASE
FreeBSD FreeBSD 4.7
FreeBSD FreeBSD 4.6.2
FreeBSD FreeBSD 4.6 -STABLE
FreeBSD FreeBSD 4.6 -RELENG
FreeBSD FreeBSD 4.6 -RELEASE-p20
FreeBSD FreeBSD 4.6 -RELEASE
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.5 -STABLEpre2002-03-07
FreeBSD FreeBSD 4.5 -STABLE
FreeBSD FreeBSD 4.5 -RELENG
FreeBSD FreeBSD 4.5 -RELEASE-p32
FreeBSD FreeBSD 4.5 -RELEASE
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.4 -STABLE
FreeBSD FreeBSD 4.4 -RELENG
FreeBSD FreeBSD 4.4 -RELENG
FreeBSD FreeBSD 4.4 -RELEASE-p42
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.3 -STABLE
FreeBSD FreeBSD 4.3 -RELENG
FreeBSD FreeBSD 4.3 -RELEASE-p38
FreeBSD FreeBSD 4.3 -RELEASE
FreeBSD FreeBSD 4.3
FreeBSD FreeBSD 4.2 -STABLEpre122300
FreeBSD FreeBSD 4.2 -STABLEpre050201
FreeBSD FreeBSD 4.2 -STABLE
FreeBSD FreeBSD 4.2 -RELEASE
FreeBSD FreeBSD 4.2
FreeBSD FreeBSD 4.1.1 -STABLE
FreeBSD FreeBSD 4.1.1 -RELEASE
FreeBSD FreeBSD 4.1.1
FreeBSD FreeBSD 4.1
FreeBSD FreeBSD 4.0 .x
FreeBSD FreeBSD 4.0 -RELENG
FreeBSD FreeBSD 4.0 alpha
FreeBSD FreeBSD 4.0
Debian Linux 3.0 sparc
Debian Linux 3.0 s/390
Debian Linux 3.0 ppc
Debian Linux 3.0 mipsel
Debian Linux 3.0 mips
Debian Linux 3.0 m68k
Debian Linux 3.0 ia-64
Debian Linux 3.0 ia-32
Debian Linux 3.0 hppa
Debian Linux 3.0 arm
Debian Linux 3.0 alpha
Debian Linux 3.0
bzip2 bzip2 1.0.2
bzip2 bzip2 1.0.1
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4
- Trustix Secure Linux 1.5
- Trustix Secure Linux 1.2
- Trustix Secure Linux 1.1
bzip2 bzip2 1.0
bzip2 bzip2 0.9.5 d
bzip2 bzip2 0.9.5 c
bzip2 bzip2 0.9.5 b
bzip2 bzip2 0.9.5 a
bzip2 bzip2 0.9 c
bzip2 bzip2 0.9 b
bzip2 bzip2 0.9 a
bzip2 bzip2 0.9
Apple Mac OS X Server 10.4.10
Apple Mac OS X Server 10.4.9
Apple Mac OS X Server 10.4.8
Apple Mac OS X Server 10.4.7
Apple Mac OS X Server 10.4.6
Apple Mac OS X Server 10.4.5
Apple Mac OS X Server 10.4.4
Apple Mac OS X Server 10.4.3
Apple Mac OS X Server 10.4.2
Apple Mac OS X Server 10.4.1
Apple Mac OS X Server 10.4
Apple Mac OS X 10.4.10
Apple Mac OS X 10.4.9
Apple Mac OS X 10.4.8
Apple Mac OS X 10.4.7
Apple Mac OS X 10.4.6
Apple Mac OS X 10.4.5
Apple Mac OS X 10.4.4
Apple Mac OS X 10.4.3
Apple Mac OS X 10.4.2
Apple Mac OS X 10.4.1
Apple Mac OS X 10.4
bzip2 bzip2 1.0.3
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11

- 不受影响的程序版本

bzip2 bzip2 1.0.3
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11

- 漏洞讨论

The 'bzip2' utility is reported prone to a security weakness that is present only when an archive is extracted into a world- or group-writeable directory. Reportedly, bzip2 employs nonatomic procedures to write a file and later changes the permissions on the newly extracted file.

A local attacker may leverage this issue to modify file permissions of target files.

This weakness is reported to affect bzip2 1.0.2 and previous versions.

- 漏洞利用

No exploit is required.

- 解决方案

The vendor has released bzip2 1.0.3 to address this issue. Please see the referenced vendor advisories for details on obtaining and applying fixes.


Sun Solaris 10.0

bzip2 bzip2 0.9 b

bzip2 bzip2 0.9.5 b

bzip2 bzip2 0.9.5 d

Turbolinux Appliance Server 1.0 Workgroup Edition

bzip2 bzip2 1.0.1

Mandriva Linux Mandrake 10.0 AMD64

Turbolinux Turbolinux Server 10.0

Turbolinux Turbolinux Desktop 10.0

Mandriva Linux Mandrake 10.1 x86_64

Apple Mac OS X 10.4.10

Apple Mac OS X 10.4.2

Apple Mac OS X 10.4.3

Apple Mac OS X 10.4.4

Apple Mac OS X 10.4.7

MandrakeSoft Corporate Server 2.1 x86_64

MandrakeSoft Corporate Server 2.1

MandrakeSoft Corporate Server 3.0

FreeBSD FreeBSD 4.11 -RELEASE-p3

FreeBSD FreeBSD 4.11 -STABLE

FreeBSD FreeBSD 5.3

FreeBSD FreeBSD 5.4 -RELENG

Turbolinux Turbolinux Workstation 7.0

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站