|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[SA10900] Symantec AntiVirus Scan Engine Race Condition Vulnerability
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Tue Feb 17 2004 - 10:19:55 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
Symantec AntiVirus Scan Engine Race Condition Vulnerability
SECUNIA ADVISORY ID:
SA10900
VERIFY ADVISORY:
http://secunia.com/advisories/10900/
CRITICAL:
Less critical
IMPACT:
Privilege escalation
WHERE:
Local system
SOFTWARE:
Symantec AntiVirus Scan Engine 4.x
DESCRIPTION:
Dr. Peter Bieringer has reported a vulnerability in Symantec
AntiVirus Scan Engine, which can be exploited by malicious, local
users to perform certain actions on a vulnerable system with
escalated privileges.
The vulnerability is caused due to a race condition when running
LiveUpdate via the shell script "liveupdate.sh". The problem is that
a log file is created insecurely with a predictable name
("/tmp/LiveUpdate.log") by default as specified in the
"/etc/liveupdate.conf" configuration file.
This can be exploited to overwrite an arbitrary file with the
privileges of the user executing the shell script via a symlink
attack when running LiveUpdate for the first time.
The vulnerability has been reported in version 4.30 for Red Hat
Linux. Other versions may also be affected.
Other minor security issues during installation regarding temporary
directory naming based on PIDs and known names were also reported.
SOLUTION:
Configure a secure log directory in "/etc/liveupdate.conf" before
running LiveUpdate the first time.
PROVIDED AND/OR DISCOVERED BY:
Dr. Peter Bieringer
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]