Junglewise Threat Intelligence

CVE-1999-1491: Red Hat Linux abuse.console privilege escalation via relative pathnames

CVE-1999-1491 · Severity: high · CVSS 7.2 · Published 1996-02-02

Technologies: Redhat Linux. Vendors: Red Hat, Redhat.

Executive brief

A vulnerability in the 'abuse' game console on Red Hat Linux 2.1 allows local users to gain full administrative control of the system. The software incorrectly looks for a helper program using a relative file path instead of a secure, fixed location. An attacker can trick the system into running a malicious program with root privileges, leading to a complete system takeover.

Technical details

The 'abuse.console' binary in Red Hat 2.1 is installed with the setuid root bit enabled. It attempts to execute a helper program named 'undrv' using a relative pathname rather than an absolute one. Because the program assumes it is being run from its own installation directory, a local attacker can execute 'abuse.console' from a directory they control (such as /tmp) containing a malicious 'undrv' executable. Since 'abuse.console' runs with root privileges, the substituted malicious program is also executed as root, allowing for local privilege escalation. The recommended mitigation is to remove the setuid bit from the affected binary.

Affected products

  • Red Hat Linux 2.1 (Red Hat) 2.1

Timeline

  • 1996-02-02: disclosed: Initial disclosure on Bugtraq by David J Meltzer
  • 1996-02-02: advisory: NVD publication date

References

Related threats