int(3678)

Vulnerability Bulletins


Acceso a dispositivos importantes en Autofs 5

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software autofs 5

Description

Se ha encontrado una vulnerabilidad en autofs 5 en sistemas Red Hat Enterprise Linux 4 y 5. La vulnerabilidad reside al no especificar la opción de montaje "nodev" para el "-hosts map" en la configuración por defecto.

Un atacante local podría obtener acceso a dispositivos importantes a través de un servidor NFS remoto y mediante la creación de archivos de dispositivos especiales en dicho servidor.

Solution



Actualización de software

Red Hat (RHSA-2007:1176-7)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
https://rhn.redhat.com/

Red Hat (RHSA-2007:1177-4)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
https://rhn.redhat.com/

Mandriva (MDVSA-2008:009 / MDVSA-2008:009-1)

Mandriva Linux 2007
X86
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/autofs-5.0.1-0.rc3.1.2mdv2007.0.i586.rpm
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/SRPMS/main/updates/autofs-5.0.1-0.rc3.1.2mdv2007.0.src.rpm
X86_64
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/autofs-5.0.1-0.rc3.1.2mdv2007.0.x86_64.rpm
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/SRPMS/main/updates/autofs-5.0.1-0.rc3.1.2mdv2007.0.src.rpm

Mandriva Linux 2007.1
X86
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/autofs-5.0.2-8.4mdv2007.1.i586.rpm
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/SRPMS/main/updates/autofs-5.0.2-8.4mdv2007.1.src.rpm
X86_64
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/autofs-5.0.2-8.4mdv2007.1.x86_64.rpm
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/SRPMS/main/updates/autofs-5.0.2-8.4mdv2007.1.src.rpm

Mandriva Linux 2008.0
X86
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/autofs-5.0.2-8.4mdv2008.0.i586.rpm
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/SRPMS/main/updates/autofs-5.0.2-8.4mdv2008.0.src.rpm
X86_64
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/autofs-5.0.2-8.4mdv2008.0.x86_64.rpm
ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/SRPMS/main/updates/autofs-5.0.2-8.4mdv2008.0.src.rpm

Standar resources

Property Value
CVE CVE-2007-6285
BID

Other resources

Red Hat Security Advisory (RHSA-2007:1176-7)
https://rhn.redhat.com/errata/RHSA-2007-1176.html

Red Hat Security Advisory (RHSA-2007:1177-4)
https://rhn.redhat.com/errata/RHSA-2007-1177.html

Mandriva Security Advisory (MDVSA-2008:009)
http://www.mandriva.com/security/advisories?name=MDVSA-2008:009

Mandriva Security Advisory (MDVSA-2008:009-1)
http://www.mandriva.com/security/advisories?name=MDVSA-2008:009-1

Version history

Version Comments Date
1.0 Aviso emitido 2008-01-03
1.1 Aviso emitido por Mandriva (MDVSA-2008:009) 2008-01-15
1.2 Aviso actializado por Mandriva (MDVSA-2008:009-1) 2008-01-22
Ministerio de Defensa
CNI
CCN
CCN-CERT