CVE-2024-45770: Pcp: pmpost symlink attack allows escalating pcp to root user

Published Sep 6, 2024
·
Updated

A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.

Other sources

This issue is somewhat similar to CVE-2023-6917 from a previous audit.

pmpost is used to append messages to the "PCP notice board". It is called from different contexts, one of which is as root from within the pmcd startup script. The program writes the message provided on the command line to the file in /var/log/pcp/NOTICES.

The directory /var/log/pcp belongs to pcp:pcp. The file is opened without passing the ONOFOLLOW flag, thus it will open symlinks placed there by the pcp user. This would allow pmpost to be coerced into creating new files in arbitrary locations, or to corrupt arbitrary existing files in the system.

Furthermore, if the NOTICES file is newly created and pmpost runs as root, then a fchown() to pcp:pcp is executed on the file. Thus it allows to pass the ownership of arbitrary newly created files in the system to pcp:pcp.

Red Hat

Affected Software

1 affected component
Performance Co-Pilot Performance Co-Pilot

Event History

Sep 6, 2024
Data Sourced
via Red Hat·05:17 PM
DescriptionSeverityAffected Software
Sep 19, 2024
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-45770?

The severity of CVE-2024-45770 is considered high due to the potential for exploiting the vulnerability by an attacker with access to a compromised Performance Co-Pilot account.

2

How do I fix CVE-2024-45770?

To fix CVE-2024-45770, update to the latest version of Performance Co-Pilot that addresses this vulnerability.

3

Who is affected by CVE-2024-45770?

CVE-2024-45770 affects systems using Performance Co-Pilot, particularly those relying on the pmpost tool.

4

What kind of attack vector does CVE-2024-45770 utilize?

CVE-2024-45770 can be exploited if an attacker gains access to a compromised Performance Co-Pilot account, enabling them to leverage the pmpost tool.

5

What is the impact of CVE-2024-45770?

The impact of CVE-2024-45770 includes potential unauthorized message logging and manipulation due to the vulnerabilities present in the pmpost tool.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203