Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2014-8169: autofs: potential privilege escalation via interpreter load path for program-based automount maps | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Johannes Segitz <jsegitz> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | jsegitz, lchiquitto, mszeredi |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
Whiteboard: | |||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Johannes Segitz
2015-02-15 13:12:27 UTC
bugbot adjusting priority is public. The Georgia Institute of Technology reports: When a program map uses an interpreted languages like python it's possible to load and execute arbitray code from a user home directory. This is because the standard environment variables are used to locate and load modules when using these languages. To avoid that we need to add a prefix to these environment names so they aren't used for this purpose. The prefix used is "AUTOFS_" and is not configurable. http://osdir.com/ml/general/2015-03/msg02418.html Fixes for openSUSE-13.[12] and Factory submitted: https://build.opensuse.org/request/show/288625 https://build.opensuse.org/request/show/288626 https://build.opensuse.org/request/show/288632 openSUSE-SU-2015:0475-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 917977 CVE References: CVE-2014-8169 Sources used: openSUSE 13.2 (src): autofs-5.1.0-2.8.1 openSUSE 13.1 (src): autofs-5.0.9-19.16.1 SUSE-SU-2015:1020-1: An update that solves one vulnerability and has four fixes is now available. Category: security (moderate) Bug References: 901448,909472,913376,916203,917977 CVE References: CVE-2014-8169 Sources used: SUSE Linux Enterprise Server 12 (src): autofs-5.0.9-8.1 SUSE Linux Enterprise Desktop 12 (src): autofs-5.0.9-8.1 released |