SuSE YaST Package Repositories Insecure Permissions Vulnerability
BID:15026
Info
SuSE YaST Package Repositories Insecure Permissions Vulnerability
| Bugtraq ID: | 15026 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 07 2005 12:00AM |
| Updated: | Oct 07 2005 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Desktop 1.0 S.u.S.E. beagle 10.0 |
| Not Vulnerable: | |
Discussion
SuSE YaST Package Repositories Insecure Permissions Vulnerability
SuSE YaST is affected by an insecure permissions vulnerability that may allow local users to overwrite package meta files.
The application copies remote repositories including ownership and permissions of the owner of the packages to the local system. If insecure permissions are associated with the packages, this issue could lead to data corruption and other attacks.
This vulnerability can aid in the exploitation of BID 14861 (SuSE YaST Local Buffer Overflow Vulnerability), which requires an attacker to overwrite YaST package meta files prior to exploitation.
SuSE YaST is affected by an insecure permissions vulnerability that may allow local users to overwrite package meta files.
The application copies remote repositories including ownership and permissions of the owner of the packages to the local system. If insecure permissions are associated with the packages, this issue could lead to data corruption and other attacks.
This vulnerability can aid in the exploitation of BID 14861 (SuSE YaST Local Buffer Overflow Vulnerability), which requires an attacker to overwrite YaST package meta files prior to exploitation.
Exploit / POC
SuSE YaST Package Repositories Insecure Permissions Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SuSE YaST Package Repositories Insecure Permissions Vulnerability
Solution:
SUSE has released advisory SUSE-SR:2005:022 to address this and other issues. Please see the referenced advisory for more information.
Solution:
SUSE has released advisory SUSE-SR:2005:022 to address this and other issues. Please see the referenced advisory for more information.
References
SuSE YaST Package Repositories Insecure Permissions Vulnerability
References:
References: