CVE-2022-0563
published 2022-02-21CVE-2022-0563: A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.43%
34.7th percentile
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | — | — |
| kernel | util-linux | < 2.37.4 | 2.37.4 |
| kernel | util-linux | — | — |
| msrc | cbl2_util-linux_2.37.4-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_util-linux_2.32.1-7_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
cisa7.8HIGH
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5896-67mw-rv4j: A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support
ghsa_unreviewed·2022-02-22
CVE-2022-0563 [MEDIUM] CWE-209 GHSA-5896-67mw-rv4j: A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
OSV
CVE-2022-0563: A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support
osv·2022-02-21·CVSS 5.5
CVE-2022-0563 [MEDIUM] CVE-2022-0563: A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
CISA
Microsoft Office Buffer Overflow Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2009-0563 [HIGH] CWE-119 Microsoft Office Buffer Overflow Vulnerability
Vulnerability: Microsoft Office Buffer Overflow Vulnerability
Affected: Microsoft Office
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-0563
Remediation Due Date: 2022-06-22
Red Hat
util-linux: partial disclosure of arbitrary files in chfn and chsh when compiled with libreadline
vendor_redhat·2022-02-14·CVSS 5.5
CVE-2022-0563 [MEDIUM] CWE-209 util-linux: partial disclosure of arbitrary files in chfn and chsh when compiled with libreadline
util-linux: partial disclosure of arbitrary files in chfn and chsh when compiled with libreadline
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
A flaw was found in the Linux kernel’s util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library
Microsoft
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. Wh
vendor_msrc·2022-02-08·CVSS 5.5
CVE-2022-0563 [MEDIUM] CWE-209 A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. Wh
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open sou
Debian
CVE-2022-0563: util-linux - A flaw was found in the util-linux chfn and chsh utilities when compiled with Re...
vendor_debian·2022·CVSS 5.5
CVE-2022-0563 [MEDIUM] CVE-2022-0563: util-linux - A flaw was found in the util-linux chfn and chsh utilities when compiled with Re...
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Trailofbits
Readline crime: exploiting a SUID logic bug
blogs_trailofbits·2023-02-16
Readline crime: exploiting a SUID logic bug
I discovered a logic bug in the `readline` dependency that partially reveals file information when parsing the file specified in the `INPUTRC` environment variable. This could allow attackers to move laterally on a box where `sshd` is running, a given user is able to login, and the user’s private key is stored in a known location (`/home/user/.ssh/id_rsa`).
This bug was reported and patched back in February 2022, and `chfn` isn’t typically provided by `util-linux` anyway, so your boxen are probably fine. I’m writing about this because the exploit is amusing, as it’s made possible due to a happy coincidence of the readline configuration file parsing functions marrying up well to the format of SSH keys—explained further in this post.
TL;DR:
```
$ INPUTRC=/root/.ssh/id_rsa chfn
Changing fi
Trailofbits
Readline crime: exploiting a SUID logic bug
blogs_trailofbits·2023-02-16
Readline crime: exploiting a SUID logic bug
readline
INPUTRC
sshd
/home/user/.ssh/id_rsa
chfn
util-linux
TL;DR:
$ INPUTRC=/root/.ssh/id_rsa chfn
Changing finger information for user.
Password:
readline: /root/.ssh/id_rsa: line 1: -----BEGIN: unknown key modifier
readline: /root/.ssh/id_rsa: line 2: b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn: no key sequence terminator
...
readline: /root/.ssh/id_rsa: line 37: avxwhoky6ozXEAAAAJcm9vdEBNQVRFAQI=: no key sequence terminator
readline: /root/.ssh/id_rsa: line 38: -----END: unknown key modifier
Office [b]: ^C
$
## Finding the bug
/etc/ld.so.preload
getenv
#define _GNU_SOURCE
#include
#include
// gcc getenv.c -fPIC -shared -ldl -o getenv.so
char *(*_real_getenv)(const char *) = 0;
char *getenv(const char *name) {
if(!_real_getenv) _real_getenv = d
https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#uhttps://security.gentoo.org/glsa/202401-08https://security.netapp.com/advisory/ntap-20220331-0002/https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#uhttps://security.gentoo.org/glsa/202401-08https://security.netapp.com/advisory/ntap-20220331-0002/
2022-02-21
Published