vendor:
Mformat
by:
krahmer@cs.uni-potsdam.de
7,2
CVSS
HIGH
Privilege Escalation Vulnerability
264
CWE
Product Name: Mformat
Affected Version From: 3.9.9
Affected Version To: 3.9.9
Patch Exists: NO
Related CWE: N/A
CPE: a:mtools:mformat
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2004
Mtools/Mformat <= 3.9.9 Local Root Exploit
It has been reported that mformat is prone to a privilege escalation vulnerability when installed as a setUID application. This issue is due to a design error allowing a user to create any arbitrary files as the root user. A local attacker could exploit this issue by forcing the creation of sensitive system files that already exist. When the application formats the specified files, the target system file will be overwritten, destroying sensitive system data. Since the files that are given permissions 0666 and owned by root, the attacker may alter overwritten system configuration files, allowing for a escalation of privileges.
Mitigation:
Ensure that the mformat application is not installed as a setUID application.