Vulnerability Bulletins |
Manejo incorrecto de variables de entorno en initscripts |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Compromiso Root |
Dificulty | Experto |
Required attacker level | Acceso remoto con cuenta |
System information |
|
Property | Value |
Affected manufacturer | GNU/Linux |
Affected software | initscripts |
Description |
|
Se ha descubierto un fallo en initscripts. La vulnerabilidad reside en el manejo de varias variables de entorno cuando se ejecuta el comando "/sbin/service". Un atacante local con permisos para ejecutar "/sbin/service" mediante sudo podría ejecutar comandos arbitrarios como usuario root. |
|
Solution |
|
Actualización de software Red Hat Red Hat Desktop (v. 4) Red Hat Enterprise Linux AS (v. 4) Red Hat Enterprise Linux ES (v. 4) Red Hat Enterprise Linux WS (v. 4) Red Hat Desktop (v. 3) Red Hat Enterprise Linux AS (v. 3) Red Hat Enterprise Linux ES (v. 3) Red Hat Enterprise Linux WS (v. 3) https://rhn.redhat.com/ SGI Advanced Linux Environment 3 / RPM / Patch 10291 ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS Advanced Linux Environment 3 / SRPM / Patch 10291 ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS |
|
Standar resources |
|
Property | Value |
CVE | CVE-2005-3629 |
BID | |
Other resources |
|
Red Hat Security Advisory (RHSA-2006:0016-18) https://rhn.redhat.com/errata/RHSA-2006-0016.html Red Hat Security Advisory (RHSA-2006:0015-14) https://rhn.redhat.com/errata/RHSA-2006-0015.html SGI Security Advisory (20060401-01-U) ftp://patches.sgi.com/support/free/security/advisories/20060401-01.U.asc |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2006-03-08 |
1.1 | Aviso emitido por Red Hat (RHSA-2006:0015-14) | 2006-03-16 |
1.2 | Aviso emitido por SGI (20060401-01-U) | 2006-04-05 |