util-linux-ng 'login' Remote Log Injection Weakness
BID:28983
Info
util-linux-ng 'login' Remote Log Injection Weakness
| Bugtraq ID: | 28983 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1926 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 29 2008 12:00AM |
| Updated: | Nov 13 2009 03:46PM |
| Credit: | Steve Grubb |
| Vulnerable: |
util-linux-ng util-linux-ng 2.13.1 util-linux-ng util-linux-ng 2.13 .1 util-linux-ng util-linux-ng 2.13 rPath rPath Linux 2 rPath Appliance Platform Linux Service 2 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya SIP Enablement Services 3.1.2 Avaya SIP Enablement Services 5.1 Avaya SIP Enablement Services 4.0 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 4.0.3 SP1 Avaya Communication Manager 3.1.4 SP2 Avaya Communication Manager 5.1 Avaya Communication Manager 5.0 SP3 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 4.1 Avaya AES 4.2.2 Avaya AES 4.2 Avaya AES 4.0 |
| Not Vulnerable: |
util-linux-ng util-linux-ng 2.13.1 .1 |
Discussion
util-linux-ng 'login' Remote Log Injection Weakness
The 'login' utility from 'util-linux-ng' is prone to a weakness that allows remote attackers to inject false information into log files. This issue occurs because the utility fails to properly sanitize user-supplied input.
Successful exploits allow malicious users to inject false information into log files. The injected information may aid in indirect attacks against log-monitoring systems or may allow attackers to obfuscate malicious activity.
Versions prior to util-linux-ng 2.13.1.1 are prone to this issue.
The 'login' utility from 'util-linux-ng' is prone to a weakness that allows remote attackers to inject false information into log files. This issue occurs because the utility fails to properly sanitize user-supplied input.
Successful exploits allow malicious users to inject false information into log files. The injected information may aid in indirect attacks against log-monitoring systems or may allow attackers to obfuscate malicious activity.
Versions prior to util-linux-ng 2.13.1.1 are prone to this issue.
Exploit / POC
util-linux-ng 'login' Remote Log Injection Weakness
To exploit this issue, attackers can use readily available network utilities or physical access to affected computers.
To exploit this issue, attackers can use readily available network utilities or physical access to affected computers.
Solution / Fix
util-linux-ng 'login' Remote Log Injection Weakness
Solution:
Updates are available. Please see the references for more information.
util-linux-ng util-linux-ng 2.13
util-linux-ng util-linux-ng 2.13 .1
util-linux-ng util-linux-ng 2.13.1
Solution:
Updates are available. Please see the references for more information.
util-linux-ng util-linux-ng 2.13
-
util-linux-ng util-linux-ng-2.13.1.1.tar.bz2
ftp://ftp.kernel.org/pub/linux/utils/util-linux-ng/v2.13/util-linux-ng -2.13.1.1.tar.bz2
util-linux-ng util-linux-ng 2.13 .1
-
util-linux-ng util-linux-ng-2.13.1.1.tar.bz2
ftp://ftp.kernel.org/pub/linux/utils/util-linux-ng/v2.13/util-linux-ng -2.13.1.1.tar.bz2
util-linux-ng util-linux-ng 2.13.1
-
util-linux-ng util-linux-ng-2.13.1.1.tar.bz2
ftp://ftp.kernel.org/pub/linux/utils/util-linux-ng/v2.13/util-linux-ng -2.13.1.1.tar.bz2
References
util-linux-ng 'login' Remote Log Injection Weakness
References:
References:
- [ANNOUNCE] util-linux-ng 2.13.1.1 (security update) (util-linux-ng)
- Changes between v2.13.1 and v2.13.1.1 (util-linux-ng)
- login: audit log injection attack via login (util-linux-ng)
- util-linux-ng Home Page (util-linux-ng)
- ASA-2009-228 util-linux security and bug fix update (RHSA-2009-0981) (Avaya)
- RHSA-2009:0981-2 util-linux security and bug fix update (Red Hat)