what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Atstake Security Advisory 04-01-27.1

Atstake Security Advisory 04-01-27.1
Posted Jan 29, 2004
Authored by David Goldsmith, Atstake | Site atstake.com

Atstake Security Advisory A012704-1 - The version of TruBlueEnvironment that is shipped with Mac OS X 10.3.x and 10.2.x takes the value of an environment variable and copies it into a buffer without performing any bounds checking. Since this buffer is stored on the stack, it is possible to overwrite the return stack frame and execute arbitrary code as root.

tags | advisory, arbitrary, root
systems | apple, osx
SHA-256 | 8ce54a8fef937890cb1f9d170aa0c3d29ca49c9cf3641d06a4d384befd8331e6

Atstake Security Advisory 04-01-27.1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


@stake, Inc.
www.atstake.com

Security Advisory

Advisory Name: TruBlueEnvironment Buffer Overflow
Release Date: 01/27/2004
Application: TruBlueEnvironment
Platform: Mac OS X 10.3.x and 10.2.x
Severity: A user with an account on the system can become root
Author: Dave G. <daveg@atstake.com>
Vendor Status: Notified, Patch Issued
CVE Candidate: CAN-2004-0089 TruBlueEnvironment Buffer Overflow
Reference: www.atstake.com/research/advisories/2004/a012704-1.txt


Overview:

TruBlueEnvironment is part of the MacOS Classic Emulator. It is
setuid root and installed by default. There is a buffer overflow
vulnerability that allows a user with interactive access to escalate
privileges to root.


Details:

TruBlueEnvironment takes the value of an environment variable and
copies it into a buffer without performing any bounds checking. Since
this buffer is stored on the stack, it is possible to overwrite the
return stack frame and execute arbitrary code as root.


Vendor Response:

This is fixed in Security Update 2004-01-26. Further information
about this update is available via:

https://docs.info.apple.com/article.html?artnum=61798

Recommendation:

Restrict access to the TruBlueEnvironment(*) executable, or remove
it entirely if it is not being used. One approach to restricting
access would be to remove global execute permissions from the
TruBlueEnvironment executable, and only allow a specific group to
execute the application. The following commands will restrict access
to the 'admin' group:

sudo chown .admin
/System/Library/CoreServices/Classic\
Startup.app/Contents/Resources/TruBlueEnvironment

sudo chmod 4750
/System/Library/CoreServices/Classic\
Startup.app/Contents/Resources/TruBlueEnvironment

(*) Located in
/System/Library/CoreServices/Classic\
Startup.app/Contents/Resources/TruBlueEnvironment


Common Vulnerabilities and Exposures (CVE) Information:

The Common Vulnerabilities and Exposures (CVE) project has assigned
the following names to these issues. These are candidates for
inclusion in the CVE list (https://cve.mitre.org), which standardizes
names for security problems.

CAN-2004-0089 TruBlueEnvironment Buffer Overflow


@stake Vulnerability Reporting Policy:
https://www.atstake.com/research/policy/

@stake Advisory Archive:
https://www.atstake.com/research/advisories/

PGP Key:
https://www.atstake.com/research/pgp_key.asc

Copyright 2004 @stake, Inc. All rights reserved.

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0 - not licensed for commercial use: www.pgp.com

iQA/AwUBQBh7qke9kNIfAm4yEQL2dQCeMd/Dje0rfRwenO9eKdVVqw5hbTsAniz3
bVqnpAekJOKpfwL2+fFdQsAp
=Be1Y
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close