3 ms·
The arb file write with uncontrolled (empty) content being turned into exec due to another process is certainly an interesting find. Usually arb file create bu
by fullspectrumdev 2y ago
The arb file write with uncontrolled (empty) content being turned into exec due to another process is certainly an interesting find.
Usually arb file create bugs with no control of content are at best a DoS unless there’s another issue at play :)
- pizzalife 2y agoThe funny thing is that this isn't the first time PAN-OS is susceptible to RCE because of "arbitrary empty file creation" (directory in this case): https://seclists.org/fulldisclosure/2017/Dec/38 https://seclists.org/fulldisclosure/2017/Dec/38
- deathanatos 2y agoReally? I'd think truly arbitrary — root access to / — writes would be an RCE. Could you not just write out a cronjob, and wait for it to execute? Or change any common binary that would easily get invoked to do some "extra" work, etc.
- pizzalife 2y agoThese are not "truly arbitrary file creation" vulnerabilities. Turning those into RCE is trivial. This is about turning an empty file creation (0 bytes) or a directory creation into code execution, via buggy cron scripts etc that process filenames.