<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: xterm has setuid enabled in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/xterm-has-setuid-enabled/m-p/3590733#M827490</link>
    <description>Hmm, looks like PHSS_30791 is related to this problem. I can reproduce the vulnerability with it, but with an older patchlevel it seems to be not vulnerable.&lt;BR /&gt;&lt;BR /&gt;Xterm needs setuid root only for marking the session to /etc/utmp. You can remove the setuid bit to avoid the vulnerability, but then commands that use utmp (like "w", "write" and "talk" for example) lose some functionality for xterm sessions.</description>
    <pubDate>Wed, 27 Jul 2005 08:11:06 GMT</pubDate>
    <dc:creator>Matti_Kurkela</dc:creator>
    <dc:date>2005-07-27T08:11:06Z</dc:date>
    <item>
      <title>xterm has setuid enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/xterm-has-setuid-enabled/m-p/3590732#M827489</link>
      <description>If you have a user belonging only to the group users you still can execute, read and write to files not belonging to the users group if you launch xterm.&lt;BR /&gt;&lt;BR /&gt;Some details to help you:&lt;BR /&gt;user u7514434 specifics:&lt;BR /&gt;[/tmp] whoami               &lt;BR /&gt;u7514434&lt;BR /&gt;[/tmp] id&lt;BR /&gt;uid=7514434(u7514434) gid=20(users)&lt;BR /&gt;&lt;BR /&gt;Another user's specifics:&lt;BR /&gt;[/tmp] whoami&lt;BR /&gt;dmsys&lt;BR /&gt;[/tmp] id&lt;BR /&gt;uid=124(dmsys) gid=150(dmtool)&lt;BR /&gt;&lt;BR /&gt;I have a script with the following security settings:&lt;BR /&gt;-rwxr-xr--   1 dmsys      dmtool          20 Jul 27 10:08 /tmp/test.sh&lt;BR /&gt;So only dmsys can launch and change the script and only users of group dmtool can launch the script but not change it. This script only echoes "test" to the screen.&lt;BR /&gt;&lt;BR /&gt;Now I login as u7514434 and launch xterm like this:&lt;BR /&gt;LOGNAME=dmsys /usr/bin/X11/xterm&lt;BR /&gt;&lt;BR /&gt;Then I do the following:&lt;BR /&gt;[/tmp] whoami&lt;BR /&gt;u7514434&lt;BR /&gt;[/tmp] id&lt;BR /&gt;uid=7514434(u7514434) gid=20(users) groups=150(dmtool)&lt;BR /&gt;[/tmp] ./test.sh&lt;BR /&gt;test&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Oeps, suddenly I belong to the group dmtool and can launch the script. I cannot change its contents.&lt;BR /&gt;&lt;BR /&gt;If however I use /usr/contrib/bin/X11/xterm instead of /usr/bin/X11/xterm then I'm not able to hack into the dmtool group.&lt;BR /&gt;&lt;BR /&gt;Other things to know:&lt;BR /&gt;HP-UX B.11.11 U 9000/800&lt;BR /&gt;[/tmp] ll /usr/bin/X11/xterm        &lt;BR /&gt;-r-sr-xr-x   1 root       bin         663552 Apr 16  2004 /usr/bin/X11/xterm&lt;BR /&gt;[/tmp] ll /usr/contrib/bin/X11/xterm&lt;BR /&gt;-r-sr-xr-x   1 root       bin         385024 Nov 14  2000 /usr/contrib/bin/X11/xterm&lt;BR /&gt;&lt;BR /&gt;For both version of xterm the setuid is active. Why is this?&lt;BR /&gt;&lt;BR /&gt;Thanks for any reply.&lt;BR /&gt;Herman.</description>
      <pubDate>Wed, 27 Jul 2005 03:38:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/xterm-has-setuid-enabled/m-p/3590732#M827489</guid>
      <dc:creator>Herman Vanbrussel</dc:creator>
      <dc:date>2005-07-27T03:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: xterm has setuid enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/xterm-has-setuid-enabled/m-p/3590733#M827490</link>
      <description>Hmm, looks like PHSS_30791 is related to this problem. I can reproduce the vulnerability with it, but with an older patchlevel it seems to be not vulnerable.&lt;BR /&gt;&lt;BR /&gt;Xterm needs setuid root only for marking the session to /etc/utmp. You can remove the setuid bit to avoid the vulnerability, but then commands that use utmp (like "w", "write" and "talk" for example) lose some functionality for xterm sessions.</description>
      <pubDate>Wed, 27 Jul 2005 08:11:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/xterm-has-setuid-enabled/m-p/3590733#M827490</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2005-07-27T08:11:06Z</dc:date>
    </item>
  </channel>
</rss>

