improper pid file handling of webgui
Closed, ResolvedPublicBUG


since the webgui is suid root, any unprivileged user (however they might get onto the system) might arbitrarily overwrite any file:

frr@fw0:~$ /usr/lib/cgi-bin-webgui -i /etc/resolv.conf
frr@fw0:~$ cat /etc/resolv.conf

don't know if that could be exploited to gain admin rights, but at least could hose the system.


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Unspecified (please specify)

Event Timeline

