vendor:
mformat
by:
krahmer@cs.uni-potsdam.de
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: mformat
Affected Version From: 3.9.2009
Affected Version To: 3.9.2009
Patch Exists: NO
Related CWE: N/A
CPE: a:mtools:mformat
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mandrake 9.2
2004
mformat Privilege Escalation Vulnerability
It has been reported that mformat is prone to a privilege escalation vulnerability when installed as a setUID application. This issue is due to a design error allowing a user to create any arbitrary files as the root user. A local attacker could exploit this issue by forcing the creation of sensitive system files that already exist. When the application formats the specified files, the target system file will be overwritten, destroying sensitive system data. Since the files that are given permissions 0666 and owned by root, the attacker may alter overwritten system configuration files, allowing for a escalation of privileges.
Mitigation:
Ensure that mformat is not installed as a setUID application.