CVE-2005-3629
published 2005-12-31CVE-2005-3629: initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.39%
31.3th percentile
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2005-03-07·CVSS 7.2
CVE-2005-3629 [HIGH] security flaw
security flaw
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.
GHSA
GHSA-p357-vv6x-p853: initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local us
ghsa_unreviewed·2022-05-03
CVE-2005-3629 [HIGH] GHSA-p357-vv6x-p853: initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local us
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3629 security flaw
bugzilla·2018-08-16·CVSS 7.2
CVE-2005-3629 [HIGH] CVE-2005-3629 security flaw
CVE-2005-3629 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.
Bugzilla
CVE-2005-3629 root shell can be gained from service if ran through sudo
bugzilla·2005-12-02·CVSS 7.2
CVE-2005-3629 [HIGH] CVE-2005-3629 root shell can be gained from service if ran through sudo
CVE-2005-3629 root shell can be gained from service if ran through sudo
+++ This bug was initially created as a clone of Bug #174825 +++
Description of problem:
By setting one of various environement variables to "valid" but yet "invalid"
values and then running service through sudo, one can gain a root shell as a
normal user.
Version-Release number of selected component (if applicable):
7.31.18.EL
How reproducible:
Always
Steps to Reproduce:
1. Run the following command:
TERM=â$TERM /bin/bash âc /bin/bashâ sudo /sbin/service network status
Note the actual service and option for the service really doen't matter.
Actual results:
Instant root shell.
Expected results:
No root shell.
Additional info:
The problem, and there may be others is that environment variables when
expand
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://secunia.com/advisories/19162http://secunia.com/advisories/19532http://securitytracker.com/id?1015732http://www.redhat.com/support/errata/RHSA-2006-0015.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0016.htmlhttp://www.securityfocus.com/bid/17038https://exchange.xforce.ibmcloud.com/vulnerabilities/25374https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11198ftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://secunia.com/advisories/19162http://secunia.com/advisories/19532http://securitytracker.com/id?1015732http://www.redhat.com/support/errata/RHSA-2006-0015.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0016.htmlhttp://www.securityfocus.com/bid/17038https://exchange.xforce.ibmcloud.com/vulnerabilities/25374https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11198
2005-12-31
Published