Vulnerability Name: | CVE-2010-3389 (CCN-64414) | ||||||||||||||||||||||||||||
Assigned: | 2010-09-30 | ||||||||||||||||||||||||||||
Published: | 2010-09-30 | ||||||||||||||||||||||||||||
Updated: | 2012-02-02 | ||||||||||||||||||||||||||||
Summary: | The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
3.0 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||
References: | Source: CCN Type: Debian Bug report logs - #598549 cluster-agents: CVE-2010-3389: insecure library loading Source: CONFIRM Type: Exploit, Patch http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598549 Source: MITRE Type: CNA CVE-2010-3389 Source: CCN Type: git.fedorahosted.org resource-agents: Improve LD_LIBRARY_PATH handling by SAP* Source: CCN Type: RHSA-2011-0264 Low: rgmanager security and bug fix update Source: CCN Type: RHSA-2011-1000 Low: rgmanager security, bug fix, and enhancement update Source: CCN Type: RHSA-2011-1580 Low: resource-agents security, bug fix, and enhancement update Source: CCN Type: SourceForge.net Web site OCF Resource Agents Source: SECUNIA Type: UNKNOWN 43372 Source: CCN Type: SA43375 resource-agents LD_LIBRARY_PATH Security Issues Source: GENTOO Type: UNKNOWN GLSA-201110-18 Source: CCN Type: OSVDB ID: 68808 OCF Resource Agents Multiple Scripts LD_LIBRARY_PATH Zero-length Directory Name Path Subversion Local Privilege Escalation Source: REDHAT Type: UNKNOWN RHSA-2011:0264 Source: REDHAT Type: UNKNOWN RHSA-2011:1000 Source: REDHAT Type: UNKNOWN RHSA-2011:1580 Source: CCN Type: BID-44359 Linux-HA OCF Resource Agents 'LD_LIBRARY_PATH' Multiple Local Privilege Escalation Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2011-0416 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=639044 Source: XF Type: UNKNOWN ocfresource-sapdatabase-privilege-esc(64414) | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |