J-Security Center

Title: Digital Unix MSGCHK MH_PROFILE Symbolic Link Vulnerability

Severity: MODERATE

Description:

The msgchk utility included with certain versions of Digital Unix contains an information disclosure vulnerability which could yield root privilege.

msgchk fails to check file permissions before opening user configuration files in the user's home directory. As a result, the user may create a symbolic link between the .mh_profile configuration file and a target file. Because root privilege is maintained on reading the config file, and symbolic links are followed, a local user is able to read the first line of data contained in any target file readable by the msgchk user. Since msgchk runs setuid root in some implementations, this allows limited information to be read from any file on the host.

Affected Products:

  • Digital (Compaq) TRU64/DIGITAL UNIX 4.0.0 D
  • Digital (Compaq) TRU64/DIGITAL UNIX 4.0.0 e
  • Digital (Compaq) TRU64/DIGITAL UNIX 4.0.0 f
  • Digital (Compaq) TRU64/DIGITAL UNIX 4.0.0 g

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.