vendor:
Performance Co-Pilot (PCP)
by:
IhaQueR
7.2
CVSS
HIGH
Improper Input Validation
20
CWE
Product Name: Performance Co-Pilot (PCP)
Affected Version From: pcp <= 2.1.11-5
Affected Version To: pcp <= 2.1.11-5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IRIX, Linux
2002
pmpost Local Root Exploit
Performance Co-Pilot (PCP) is a set of services to support system-level performance monitoring developed by SGI. It has traditionally been an IRIX product, however SGI has made it open source and it is now available for Linux systems. One of the utilities that ships with PCP is called 'pmpost'. It is often installed setuid root by default. When writing to the 'NOTICES' file in its user-definable log directory, 'pmpost' will follow symbolic links. Since the data written is user-supplied (the command-line arguments), it is possible to gain superuser privileges if 'pmpost' is setuid root.
Mitigation:
Ensure that 'pmpost' is not installed setuid root, or that the log directory is not writable by non-privileged users.