Nessus Insecure Temporary File Creation Vulnerabiliry
BID:10784
Info
Nessus Insecure Temporary File Creation Vulnerabiliry
| Bugtraq ID: | 10784 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 22 2004 12:00AM |
| Updated: | Jul 22 2004 12:00AM |
| Credit: | Cyrille Barthelemy disclosed this vulnerability to the vendor. |
| Vulnerable: |
Nessus Nessus 2.1 .0 Nessus Nessus 2.0.11 Nessus Nessus 2.0.10 Nessus Nessus 2.0.9 Nessus Nessus 2.0.8 Nessus Nessus 2.0.7 Nessus Nessus 2.0.6 Nessus Nessus 2.0.5 Nessus Nessus 2.0.4 Nessus Nessus 2.0.3 Nessus Nessus 2.0.2 Nessus Nessus 2.0.1 Nessus Nessus 2.0 |
| Not Vulnerable: |
Nessus Nessus 2.1.1 Nessus Nessus 2.0.12 |
Discussion
Nessus Insecure Temporary File Creation Vulnerabiliry
Nessus is reported to be vulnerable to an insecure temporary file creation vulnerability.
This vulnerability presents itself in the 'nessus-adduser' script. This script is used to add users to the Nessus application. These users are independent of the system user database, and are used to define access roles and limits in the application.
When creating new users, Nessus insecurely creates a temporary file.
A non-privileged user with interactive access could overwrite any file on the system with superuser privileges. The attacker does not control the data being written, just the location of the file.
An attacker could also exploit this issue to modify the rules assigned to the new nessus user, allowing or denying access to scan hosts within Nessus.
Versions of 2.0.x prior to 2.0.12 and the experimental version 2.1.0 are reported to be vulnerable to this issue.
Nessus is reported to be vulnerable to an insecure temporary file creation vulnerability.
This vulnerability presents itself in the 'nessus-adduser' script. This script is used to add users to the Nessus application. These users are independent of the system user database, and are used to define access roles and limits in the application.
When creating new users, Nessus insecurely creates a temporary file.
A non-privileged user with interactive access could overwrite any file on the system with superuser privileges. The attacker does not control the data being written, just the location of the file.
An attacker could also exploit this issue to modify the rules assigned to the new nessus user, allowing or denying access to scan hosts within Nessus.
Versions of 2.0.x prior to 2.0.12 and the experimental version 2.1.0 are reported to be vulnerable to this issue.
Exploit / POC
Nessus Insecure Temporary File Creation Vulnerabiliry
No exploit is required.
No exploit is required.
Solution / Fix
Nessus Insecure Temporary File Creation Vulnerabiliry
Solution:
The vendor has released new versions of the package, resolving this issue.
Gentoo has released an advisory (GLSA 200408-11) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to upgrade their computers:
emerge sync
emerge -pv ">=net-analyzer/nessus-2.0.12"
emerge ">=net-analyzer/nessus-2.0.12"
OpenBSD has committed a fix for this issue in the ports tree of OpenBSD-current as of 13 Aug 2004.
Nessus Nessus 2.0
Nessus Nessus 2.0.1
Nessus Nessus 2.0.10
Nessus Nessus 2.0.11
Nessus Nessus 2.0.2
Nessus Nessus 2.0.3
Nessus Nessus 2.0.4
Nessus Nessus 2.0.5
Nessus Nessus 2.0.6
Nessus Nessus 2.0.7
Nessus Nessus 2.0.8
Nessus Nessus 2.0.9
Nessus Nessus 2.1 .0
Solution:
The vendor has released new versions of the package, resolving this issue.
Gentoo has released an advisory (GLSA 200408-11) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to upgrade their computers:
emerge sync
emerge -pv ">=net-analyzer/nessus-2.0.12"
emerge ">=net-analyzer/nessus-2.0.12"
OpenBSD has committed a fix for this issue in the ports tree of OpenBSD-current as of 13 Aug 2004.
Nessus Nessus 2.0
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.1
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.10
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.11
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.2
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.3
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.4
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.5
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.6
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.7
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.8
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.0.9
-
Nessus Nessus 2.0.12
http://ftp.nessus.org/nessus/nessus-2.0.12/src/
Nessus Nessus 2.1 .0
-
Nessus Nessus 2.1.1
http://ftp.nessus.org/nessus/nessus-2.1.1/src/
References
Nessus Insecure Temporary File Creation Vulnerabiliry
References:
References:
- [Nessus-announce] Nessus 2.0.12 and 2.1.1 available (Nessus)
- Nessus Home Page (Tenable Network Security)