Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
BID:17842
Info
Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
| Bugtraq ID: | 17842 |
| Class: | Design Error |
| CVE: |
CVE-2006-2110 |
| Remote: | No |
| Local: | Yes |
| Published: | May 04 2006 12:00AM |
| Updated: | May 19 2006 09:48PM |
| Credit: | Jan Rekorajski reported this issue to the vendor. |
| Vulnerable: |
VServer Linux-VServer 2.1 VServer Linux-VServer 2.0.1 VServer Linux-VServer 2.0 VServer Linux-VServer 1.9.1 VServer Linux-VServer 0.9.12 VServer Linux-VServer 0.9.10 VServer Linux-VServer 2.0-rc2 VServer Linux-VServer 2.0-rc1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
VServer Linux-VServer 2.1.1 -rc18 VServer Linux-VServer 2.0.2 -rc18 |
Discussion
Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
The Linux-VServer package is susceptible to a vulnerability regarding insecure guest-context capabilities. This issue is due to the kernel's failure to properly enforce security restrictions in guest hosts.
This issue allows unprivileged users in guest hosts to perform various operations that should be restricted to superusers. By exploiting this issue, attackers can launch various attacks in guest hosts.
Note that this issue allows attackers to execute privileged operations only in the guest context, not in the host context.
The Linux-VServer package is susceptible to a vulnerability regarding insecure guest-context capabilities. This issue is due to the kernel's failure to properly enforce security restrictions in guest hosts.
This issue allows unprivileged users in guest hosts to perform various operations that should be restricted to superusers. By exploiting this issue, attackers can launch various attacks in guest hosts.
Note that this issue allows attackers to execute privileged operations only in the guest context, not in the host context.
Exploit / POC
Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
Attackers exploit this issue by using standard systems-administration utilities.
Attackers exploit this issue by using standard systems-administration utilities.
Solution / Fix
Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
Solution:
The vendor has released a patch to address this issue.
Versions 2.0.2-rc18 and 2.1.1-rc18 are also available; they contain this fix.
Please see the references for more information, fixes, and vendor advisories.
VServer Linux-VServer 2.0-rc2
VServer Linux-VServer 2.0-rc1
VServer Linux-VServer 1.9.1
VServer Linux-VServer 2.0
VServer Linux-VServer 2.0.1
VServer Linux-VServer 2.1
Solution:
The vendor has released a patch to address this issue.
Versions 2.0.2-rc18 and 2.1.1-rc18 are also available; they contain this fix.
Please see the references for more information, fixes, and vendor advisories.
VServer Linux-VServer 2.0-rc2
-
VServer delta-vxcapable-fix01a.diff
http://vserver.13thfloor.at/Stuff/delta-vxcapable-fix01a.diff
VServer Linux-VServer 2.0-rc1
-
VServer delta-vxcapable-fix01a.diff
http://vserver.13thfloor.at/Stuff/delta-vxcapable-fix01a.diff
VServer Linux-VServer 1.9.1
-
VServer delta-vxcapable-fix01a.diff
http://vserver.13thfloor.at/Stuff/delta-vxcapable-fix01a.diff
VServer Linux-VServer 2.0
-
VServer delta-vxcapable-fix01a.diff
http://vserver.13thfloor.at/Stuff/delta-vxcapable-fix01a.diff
VServer Linux-VServer 2.0.1
-
VServer delta-vxcapable-fix01a.diff
http://vserver.13thfloor.at/Stuff/delta-vxcapable-fix01a.diff
VServer Linux-VServer 2.1
-
VServer delta-vxcapable-fix01a.diff
http://vserver.13thfloor.at/Stuff/delta-vxcapable-fix01a.diff
References
Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
References:
References:
- [Vserver] [SECURITY] ccaps not limited to root inside a guest (VServer)
- VServer Home Page (VServer)