OSVDB ID: 535

Title: UNIX-V6 su File Descriptor Exhaustion Local Privilege Escalation

Info

Disclosure

Unknown

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

UNIX-V6 contains a flaw that may allow a local attacker to gain increased privileges. The flaw occurs when an attacker intentionally exhausts all file descriptors before executing the 'su' program. In such a case, 'su' would invoke a super-user shell instead of failing to execute.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public

Solution

The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem. It is recommended that an alternate software package be used in its place.

Products

UNIX-V6

UNIX-V6

Unknown or Unspecified

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/535