Executive brief
rxvt is a terminal emulator used in older Linux distributions to provide a command-line interface within a graphical environment. A vulnerability exists where the program fails to drop administrative (root) privileges before executing a user-defined printing command. A local user with access to the system can exploit this to run any command with full administrative rights, leading to a complete takeover of the machine.
Technical details
The rxvt terminal emulator, when compiled with the PRINT_PIPE option and installed with the setuid root bit (often required for utmp logging), fails to drop privileges before invoking a pipe to a printer command. An attacker can use the '-print-pipe' command-line argument to specify an arbitrary executable instead of the intended printer utility. By sending the VT100 'printer-on' escape sequence (ESC[5i) to the terminal, the attacker triggers a popen() call that executes the malicious program with root privileges. This vulnerability affects early Linux distributions like Slackware 3.0 and RedHat 2.1. A temporary mitigation is to remove the setuid bit from the rxvt binary.
Affected products
- rxvt project rxvt Slackware 3.0, RedHat 2.1, and other systems where rxvt is suid root
Timeline
- 1996-01-02: disclosed: Initial bugtraq disclosure by David J Meltzer
- 1996-01-02: advisory: NVD published date