SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   acpid Vendors:   acpid.sourceforge.net
acpid Log File Permissions May Let Local Users Gain Elevated Privileges
SecurityTracker Alert ID:  1023284
SecurityTracker URL:  http://securitytracker.com/id/1023284
CVE Reference:   CVE-2009-4033   (Links to External Site)
Date:  Dec 7 2009
Impact:   Execution of arbitrary code via local system, Root access via local system, User access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  

Description:   A vulnerability was reported in acpid on Red Hat Enterprise Linux. A local user can obtain elevated privileges on the target system.

The acpid daemon may create its log file ('/var/log/acpid') with random permissions on some Red Hat Enterprise Linux systems. If the log file is created with the set user id (setuid) or set group id (setgid) permissions and with world-writable permissions, a local user can modify and execute the file to gain elevated privileges.

The vulnerability is due to a Red Hat-specific patch (acpid-1.0.4-fd.patch) included in the Red Hat Enterprise Linux 5 acpid package. The upstream version is not affected.

Impact:   A local user can obtain elevated privileges on the target system.
Solution:   Red Hat has issued a fix.

The Red Hat advisory is available at:

https://rhn.redhat.com/errata/RHSA-2009-1642.html

Vendor URL:  acpid.sourceforge.net/ (Links to External Site)
Cause:   Access control error
Underlying OS:  Linux (Red Hat Enterprise)
Underlying OS Comments:  5

Message History:   None.


 Source Message Contents

Subject:  [RHSA-2009:1642-02] Important: acpid security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: acpid security update
Advisory ID:       RHSA-2009:1642-02
Product:           Red Hat Enterprise Linux
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2009-1642.html
Issue date:        2009-12-07
CVE Names:         CVE-2009-4033 
=====================================================================

1. Summary:

An updated acpid package that fixes one security issue is now available for
Red Hat Enterprise Linux 5.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux (v. 5 server) - i386, ia64, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64

3. Description:

acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.

It was discovered that acpid could create its log file ("/var/log/acpid")
with random permissions on some systems. A local attacker could use this
flaw to escalate their privileges if the log file was created as
world-writable and with the setuid or setgid bit set. (CVE-2009-4033)

Please note that this flaw was due to a Red Hat-specific patch
(acpid-1.0.4-fd.patch) included in the Red Hat Enterprise Linux 5 acpid
package.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network.  Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

515062 - /var/log/acpid has improper permissions
542926 - CVE-2009-4033 acpid: log file created with random permissions

6. Package List:

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/acpid-1.0.4-9.el5_4.1.src.rpm

i386:
acpid-1.0.4-9.el5_4.1.i386.rpm
acpid-debuginfo-1.0.4-9.el5_4.1.i386.rpm

x86_64:
acpid-1.0.4-9.el5_4.1.x86_64.rpm
acpid-debuginfo-1.0.4-9.el5_4.1.x86_64.rpm

Red Hat Enterprise Linux (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/acpid-1.0.4-9.el5_4.1.src.rpm

i386:
acpid-1.0.4-9.el5_4.1.i386.rpm
acpid-debuginfo-1.0.4-9.el5_4.1.i386.rpm

ia64:
acpid-1.0.4-9.el5_4.1.ia64.rpm
acpid-debuginfo-1.0.4-9.el5_4.1.ia64.rpm

x86_64:
acpid-1.0.4-9.el5_4.1.x86_64.rpm
acpid-debuginfo-1.0.4-9.el5_4.1.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4033
http://www.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2009 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFLHVa6XlSAg2UNWIIRAgy1AJ4m4BDmOZBAzVEH/driGf7fEd6a1wCfSOFY
GR8nSSBJMB41JNgS2R+VmbI=
=Euil
-----END PGP SIGNATURE-----


-- 
Enterprise-watch-list mailing list
Enterprise-watch-list@redhat.com
https://www.redhat.com/mailman/listinfo/enterprise-watch-list

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC