PT-2018-3076 · Novell+6 · Zenworks Configuration Management+6

Xiao Jin

·

Publicado

2018-07-30

·

Atualizado

2019-12-11

·

CVE-2018-20856

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.18.7 ZENworks Configuration Management (ZCM) version 10.3 and versions 11.2 prior to 11.2.4
Description An issue was discovered in the Linux kernel related to a use-after-free error in the blk drain queue() function in block/blk-core.c due to mishandling of a certain error case. This issue may allow an attacker to impact data integrity, gain unauthorized access to protected information, and cause a denial of service. Additionally, a vulnerability in the ZENworks Configuration Management (ZCM) server allows remote attackers to perform directory traversal attacks and load and execute arbitrary programs by sending a request to TCP port 443 due to improper authentication for the zenworks/jsp/index.jsp file.
Recommendations For Linux kernel versions prior to 4.18.7, update to version 4.18.7 or later to resolve the issue. For ZENworks Configuration Management (ZCM) version 10.3, update to a version later than 10.3. For ZENworks Configuration Management (ZCM) versions 11.2 prior to 11.2.4, update to version 11.2.4 or later. As a temporary workaround for the Linux kernel issue, consider restricting access to the block/blk-core.c file until a patch is available. For the ZENworks Configuration Management (ZCM) issue, restrict access to the zenworks/jsp/index.jsp file to minimize the risk of exploitation.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2333
ALT-PU-2018-2336
ALT-PU-2019-1433
BDU:2019-03624
CESA-2019_3055
CVE-2018-20856
DLA-1885-1
DSA-4497-1
RHSA-2019:3055
RHSA-2019:3076
RHSA-2019:3089
RHSA-2019:3217
RHSA-2019_3055
RHSA-2019_3089
RHSA-2020:0100
RHSA-2020:0103
RHSA-2020:0543
RHSA-2020:0664
RHSA-2020:0698
SUSE-SU-2019:2263-1
SUSE-SU-2019:2299-1
SUSE-SU-2019:3228-1
SUSE-SU-2019:3232-1
SUSE-SU-2019:3252-1
SUSE-SU-2019:3258-1
SUSE-SU-2019:3260-1
SUSE-SU-2019:3261-1
USN-4094-1
USN-4116-1
USN-4118-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu
Zenworks Configuration Management