Junglewise Threat Intelligence

CVE-2016-6253: NetBSD mail.local symlink race condition privilege escalation

CVE-2016-6253 · Severity: high · CVSS 7.8 · Published 2017-01-20

Executive brief

A vulnerability in the mail delivery component of NetBSD allows a local user to gain full administrative control over the system. By exploiting a timing flaw during mail processing, an attacker can trick the system into changing the ownership of critical system files. This can lead to unauthorized data access, system instability, or a complete takeover of the affected machine.

Technical details

A symlink race condition exists in the mail.local(8) utility, which is typically installed with the setuid root bit enabled. The vulnerability occurs because the program uses lstat(2) to verify that a user's mailbox (e.g., /var/mail/$USER) is not a symbolic link before opening it, but does not perform this check atomically. A local attacker can exploit this Time-of-Check to Time-of-Use (TOCTOU) window to replace the mailbox with a symlink pointing to a sensitive system file (like /etc/passwd or /usr/libexec/atrun). Consequently, mail.local may perform an fchown(2) or append data to the target file as the root user. This can be leveraged to achieve full local privilege escalation to root.

Affected products

  • NetBSD Foundation NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, 7.0, and 7.0.1

Timeline

  • 2016-07-19: patched: Fixes committed to NetBSD-current and release branches.
  • 2016-07-20: advisory: NetBSD Security Advisory 2016-006 released.
  • 2017-01-20: disclosed: NVD publication date.

References