J-Security Center

Title: 4D WebStar Symbolic Link Vulnerability

Severity: HIGH

Description:

4D WebStar is an application providing web, FTP and email services for Apple Mac OS X.

4D WebStar is reportedly vulnerable to a symbolic link vulnerability. This issue is due to a design error that causes the application to open files without properly verifying their existence or their absolute location.

The problem presents itself when the affected application attempts to open up a file; it uses a relative path from the current working directory when opening files. This may be used to create arbitrary files on the system in directories writable by the affected process. Furthermore the default umask creates such files with world readable and writable attributes. This can be leveraged by creating file associated with the cron subsystem, facilitating privilege escalation.

Successful exploitation of this issue will allow an attacker to write to arbitrary files writable by the affected application, facilitating privilege escalation.

Affected Products:

  • 4D WebSTAR 4.0.0
  • 4D WebSTAR 5.2.0
  • 4D WebSTAR 5.2.1
  • 4D WebSTAR 5.2.2
  • 4D WebSTAR 5.2.3
  • 4D WebSTAR 5.2.4
  • 4D WebSTAR 5.3.0
  • 4D WebSTAR 5.3.1
  • 4D WebSTAR 5.3.2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.