Junglewise Threat Intelligence

CVE-1999-1210: Digital UNIX xterm arbitrary file overwrite via core dump symlink

CVE-1999-1210 · Severity: high · CVSS 7.2 · Published 1997-11-12

Technologies: Digital Equipment Corporation Digital Unix. Vendors: Digital Equipment Corporation.

Executive brief

A vulnerability in the xterm terminal emulator on Digital UNIX 4.0B allows local users to overwrite critical system files. By manipulating environment variables to force the application to crash, a user can redirect the resulting error data (core dump) to overwrite sensitive files like the password database. This can lead to a complete system failure or allow an attacker to gain administrative control.

Technical details

The xterm executable in Digital UNIX 4.0B (specifically after applying patch kit 5) is installed with setuid root privileges and is vulnerable to a symlink-based file overwrite. When the DISPLAY environment variable is set to an unreachable or invalid address, xterm triggers a segmentation fault during the XtOpenApplication() call. Because the process is running with elevated privileges, it may write a core dump file to the current directory. An attacker can create a symbolic link named 'core' in the working directory pointing to a sensitive system file (e.g., /etc/passwd or /vmunix), causing xterm to overwrite that file with core dump data upon crashing.

Affected products

  • Digital Equipment Corporation (DEC) Digital UNIX 4.0B with patch kit 5

Timeline

  • 1997-11-12: disclosed: Public disclosure on Bugtraq mailing list
  • 1997-11-12: advisory: NVD publication date

References

Related threats