Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability
BID:55066
Info
Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability
| Bugtraq ID: | 55066 |
| Class: | Design Error |
| CVE: |
CVE-2012-3417 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2012 12:00AM |
| Updated: | Jun 27 2013 07:21PM |
| Credit: | Tomas Hoger |
| Vulnerable: |
Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 CentOS CentOS 5 Avaya IQ 4.1 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IQ 4.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 |
| Not Vulnerable: | |
Discussion
Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability
Linux DiskQuota is prone to a security-bypass vulnerability.
Successful exploits may allow an attacker to bypass certain security restrictions and to perform unauthorized actions; this may aid in launching further attacks.
Linux DiskQuota versions prior to 3.17 are vulnerable.
Linux DiskQuota is prone to a security-bypass vulnerability.
Successful exploits may allow an attacker to bypass certain security restrictions and to perform unauthorized actions; this may aid in launching further attacks.
Linux DiskQuota versions prior to 3.17 are vulnerable.
Exploit / POC
Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability
An attacker may exploit this issue using commonly available tools.
An attacker may exploit this issue using commonly available tools.
Solution / Fix
Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability
References:
References:
- (CVE-2012-3417) CVE-2012-3417 quota: incorrect use of tcp_wrappers (Red Hat)
- Linux DiskQuota Homepage (Linux DiskQuota)
- Odd use of tcp_wrappers in rquota (jkar8572)
- ASA-2013-028 quota security and bug fix update (RHSA-2013-0120) (Avaya)
- quota security and bug fix update (RHSA-2013-0120) (Avaya)