BusyBox CVE-2014-9645 Local Security Bypass Vulnerability
BID:72324
Info
BusyBox CVE-2014-9645 Local Security Bypass Vulnerability
| Bugtraq ID: | 72324 |
| Class: | Design Error |
| CVE: |
CVE-2014-9645 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 27 2015 12:00AM |
| Updated: | Jan 12 2017 08:09AM |
| Credit: | Matthias Krause |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM SmartCloud Entry 3.2 Appliance fixpack 22 IBM SmartCloud Entry 3.2 Appliance fixpack 21 IBM SmartCloud Entry 3.2 Appliance fix pack 2 IBM SmartCloud Entry 3.2 Appliance fix pack 1 IBM SmartCloud Entry 3.2 IBM SmartCloud Entry 3.1 IBM SmartCloud Entry 2.2 Appliance fix pack 6 IBM SmartCloud Entry 2.2 Appliance fix pack 4 IBM SmartCloud Entry 2.2 IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0 IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0 IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM Security Network Protection 5.3.3 IBM Security Network Protection 5.3.2 IBM Security Network Protection 5.3.1 IBM Security Network Protection 5.3.2.4 IBM Security Network Protection 5.3.2.3 IBM Security Network Protection 5.3.2.2 IBM Security Network Protection 5.3.2.1 IBM Security Network Protection 5.3.1.9 IBM Security Network Protection 5.3.1.8 IBM Security Network Protection 5.3.1.7 IBM Security Network Protection 5.3.1.6 IBM Security Network Protection 5.3.1.5 IBM Security Network Protection 5.3.1.4 IBM Security Network Protection 5.3.1.3 IBM Security Network Protection 5.3.1.2 IBM Security Network Protection 5.3.1.10 IBM Security Network Protection 5.3.1.1 Gentoo Linux BusyBox BusyBox 1.22 |
| Not Vulnerable: |
IBM Security Network Protection 5.3.3.1 IBM Security Network Protection 5.3.2.5 IBM Security Network Protection 5.3.1.11 |
Discussion
BusyBox CVE-2014-9645 Local Security Bypass Vulnerability
BusyBox is prone to a local security bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
BusyBox is prone to a local security bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Exploit / POC
BusyBox CVE-2014-9645 Local Security Bypass Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
BusyBox CVE-2014-9645 Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva busybox-1.20.2-1.3.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva busybox-static-1.20.2-1.3.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
BusyBox CVE-2014-9645 Local Security Bypass Vulnerability
References:
References:
- BusyBox Homepage (BusyBox)
- CVE-2014-9645 busybox: unprivileged arbitrary module load via basename abuse (Red Hat Bugzilla)
- modprobe wrongly accepts paths as module names (BusyBox)
- isg3T1024734:Vulnerabilities in Busybox affect IBM SmartCloud Entry (CVE-2014-46 (IBM)
- swg21990083: Security Bulletin: Vulnerabilities in busybox affect IBM Security N (IBM)