oss-security February 2011 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: [oss-security] CVE request: FreeBSD/OS X crontab i

[oss-security] CVE request: FreeBSD/OS X crontab information leakage

From: Dan Rosenberg <dan.j.rosenberg_at_nospam>
Date: Mon Feb 28 2011 - 20:26:41 GMT
To: oss-security@lists.openwall.com

Details here:
http://marc.info/?l=full-disclosure&m=129891323028897&w=2

There are three leaks, each of which amounts to a minor DAC bypass.

1. Leakage of file/directory existence via stat() calls (e.g.
determining if a file exists regardless of search permissions on
directories)

2. Leakage of directory existence via realpath()

3. Arbitrary MD5 comparison (e.g. ability to determine if any two
files have identical MD5 hashes, regardless of read permissions on
those files)

No preference for single vs. multiple CVEs.

-Dan