CVE-2013-2207
published 2013-10-09CVE-2013-2207: pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission…
PriorityP49low2.6CVSS 2.0
AVLACHAuNCPIPAN
EPSS
0.35%
27.5th percentile
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.21-1 (bookworm) | glibc 2.21-1 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.8 | 2.19-0ubuntu6.8 |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.9 | 2.19-0ubuntu6.9 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | glibc | <= 2.17 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g33j-hgrw-88mh: pt_chown in GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2022-05-17
CVE-2013-2207 [LOW] GHSA-g33j-hgrw-88mh: pt_chown in GNU C Library (aka glibc or libc6) before 2
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
OSV
eglibc, glibc vulnerabilities
osv·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] eglibc, glibc vulnerabilities
eglibc, glibc vulnerabilities
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE
OSV
CVE-2013-2207: pt_chown in GNU C Library (aka glibc or libc6) before 2
osv·2013-10-09·CVSS 2.6
CVE-2013-2207 [LOW] CVE-2013-2207: pt_chown in GNU C Library (aka glibc or libc6) before 2
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
Ubuntu
GNU C Library regression
vendor_ubuntu·2016-05-26·CVSS 2.6
CVE-2014-9761 [LOW] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2985-1 introduced a regression in the GNU C Library.
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
th
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2016-05-25·CVSS 2.6
CVE-2013-2207 [LOW] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
Red Hat
(pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal
vendor_redhat·2013-07-16·CVSS 2.6
CVE-2013-2207 [LOW] (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal
(pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
Statement: Not Vulnerable. This issue does not affect the version of glibc as shipped with Red Hat Enterprise Linux 5 and 6.
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-2207: glibc - pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly che...
vendor_debian·2013·CVSS 2.6
CVE-2013-2207 [LOW] CVE-2013-2207: glibc - pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly che...
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
Scope: local
bookworm: resolved (fixed in 2.21-1)
bullseye: resolved (fixed in 2.21-1)
forky: resolved (fixed in 2.21-1)
sid: resolved (fixed in 2.21-1)
trixie: resolved (fixed in 2.21-1)
No detection rules found.
No public exploits indexed.
Bugzilla
glibc: CVE-2013-2207 glibc (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal [fedora-all]
bugzilla·2013-07-16·CVSS 2.6
CVE-2013-2207 [LOW] glibc: CVE-2013-2207 glibc (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal [fedora-all]
glibc: CVE-2013-2207 glibc (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2013-2207 glibc (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal
bugzilla·2013-06-20·CVSS 2.6
CVE-2013-2207 [LOW] CVE-2013-2207 glibc (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal
CVE-2013-2207 glibc (pt_chown): Improper pseudotty ownership and permissions changes when granting access to the slave pseudoterminal
A security flaw was found in the way pt_chown, a helper function for grantpt(3) to change ownership and permissions of pseudoterminal, of glibc, the collection of GNU libc libraries, performed pseudotty ownership and permission changes when granting access to the slave pseudoterminal. A local attacker could use this flaw to obtain unauthorized read / write access at the pseudoterminal of their choose by using a specially-crafted (by attacker supplied) file system.
Acknowledgements:
Red Hat would like to thank Martin Carpenter of Citco for reporting this issue.
Discussion:
This issue has been assigned CVE-2013-2207
---
Created attachment 765000
remove
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://secunia.com/advisories/55113http://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.ubuntu.com/usn/USN-2985-1http://www.ubuntu.com/usn/USN-2985-2https://bugzilla.redhat.com/show_bug.cgi?id=976408https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=15755https://sourceware.org/ml/libc-alpha/2013-08/msg00160.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://secunia.com/advisories/55113http://www.mandriva.com/security/advisories?name=MDVSA-2013:283http://www.ubuntu.com/usn/USN-2985-1http://www.ubuntu.com/usn/USN-2985-2https://bugzilla.redhat.com/show_bug.cgi?id=976408https://security.gentoo.org/glsa/201503-04https://sourceware.org/bugzilla/show_bug.cgi?id=15755https://sourceware.org/ml/libc-alpha/2013-08/msg00160.html
2013-10-09
Published