cPanel .htaccess modify ownership of files
| cpanel-htaccess-modify-ownership (17780) |
Description:
cPanel could allow a remote authenticated attacker to modify the ownership of arbitrary files on the system. The .htaccess file is created with root privileges when FrontPage extensions are turned on or off. By creating a hardlink from an arbitrary file on the system to the .htaccess file, a remote authenticated attacker could obtain unauthorized ownership of the linked file.
Consequences:
Gain Privileges
Remedy:
No remedy available as of July 9, 2011.
References:
- Full-Disclosure Mailing List, Mon Oct 18 2004 - 04:51:02 CDT: cPanel hardlink chown issue.
- BID-11449: cPanel Remote Backup Information Disclosure Vulnerability
- BID-11455: cPanel Front Page Extension Installation File Ownership Vulnerability
- CVE-2004-1603: cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
- SA12865: cPanel Manipulation and Disclosure of Sensitive information Vulnerabilities
Platforms Affected:
- cPanel cPanel 9.4.1-RELEASE-64
Reported:
Oct 18, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
