Executive brief
A vulnerability in the mail delivery component of NetBSD allows a local user to gain full administrative control over the system. By exploiting a timing flaw during mail processing, an attacker can trick the system into changing the ownership of critical system files. This can lead to unauthorized data access, system instability, or a complete takeover of the affected machine.
Technical details
A symlink race condition exists in the mail.local(8) utility, which is typically installed with the setuid root bit enabled. The vulnerability occurs because the program uses lstat(2) to verify that a user's mailbox (e.g., /var/mail/$USER) is not a symbolic link before opening it, but does not perform this check atomically. A local attacker can exploit this Time-of-Check to Time-of-Use (TOCTOU) window to replace the mailbox with a symlink pointing to a sensitive system file (like /etc/passwd or /usr/libexec/atrun). Consequently, mail.local may perform an fchown(2) or append data to the target file as the root user. This can be leveraged to achieve full local privilege escalation to root.
Affected products
- NetBSD Foundation NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, 7.0, and 7.0.1
Timeline
- 2016-07-19: patched: Fixes committed to NetBSD-current and release branches.
- 2016-07-20: advisory: NetBSD Security Advisory 2016-006 released.
- 2017-01-20: disclosed: NVD publication date.
References
- http://akat1.pl/?id=2
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2016-006.txt.asc
- http://packetstormsecurity.com/files/138021/NetBSD-mail.local-8-Local-Root.html
- http://www.rapid7.com/db/modules/exploit/unix/local/netbsd_mail_local
- http://www.securityfocus.com/bid/92101
- http://www.securitytracker.com/id/1036429
- https://www.exploit-db.com/exploits/40141/