PT-2008-1074 · Sblim+3 · Sblim-Cmpi-Nfsv3-Test+22

Published

2008-06-24

·

Updated

2023-02-13

·

CVE-2008-1951

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions sblim-cmpi-base-test versions 1.5.4 through 1.5.5 sblim-cmpi-base-devel versions 1.5.4 through 1.5.5 sblim-cmpi-fsvol-test version 1.4.4 sblim-cmpi-fsvol-devel version 1.4.4 sblim-cmpi-network-test version 1.3.8 sblim-cmpi-network-devel version 1.3.8 sblim-cmpi-dns-test version 1 sblim-cmpi-dns-devel version 1 sblim-cmpi-samba-test version 1 sblim-cmpi-samba-devel version 1 sblim-cmpi-sysfs-test version 1.1.9 sblim-cmpi-syslog-test version 0.7.11 sblim-cmpi-nfsv3-test version 1.0.14 sblim-cmpi-nfsv4-test version 1.0.12 sblim-cmpi-params-test version 1.2.6 sblim-gather-test version 2.1.2 sblim-gather-devel version 2.1.2 sblim-testsuite version 1.2.4 sblim-tools-libra-devel version 0.2.3 sblim version 1 sblim version 1-31.el5 2.1
Description The issue is related to an untrusted search path vulnerability in certain Red Hat build scripts for Standards Based Linux Instrumentation for Manageability (sblim) libraries. This vulnerability can be exploited locally, allowing attackers to gain privileges via a malicious library in a certain subdirectory of /var/tmp. The exploitation is related to an incorrect RPATH setting, as demonstrated by a malicious libc.so library for tog-pegasus. The vulnerability may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For sblim-cmpi-base-test versions 1.5.4 through 1.5.5, update to a fixed version. For sblim-cmpi-base-devel versions 1.5.4 through 1.5.5, update to a fixed version. For sblim-cmpi-fsvol-test version 1.4.4, update to a fixed version. For sblim-cmpi-fsvol-devel version 1.4.4, update to a fixed version. For sblim-cmpi-network-test version 1.3.8, update to a fixed version. For sblim-cmpi-network-devel version 1.3.8, update to a fixed version. For sblim-cmpi-dns-test version 1, update to a fixed version. For sblim-cmpi-dns-devel version 1, update to a fixed version. For sblim-cmpi-samba-test version 1, update to a fixed version. For sblim-cmpi-samba-devel version 1, update to a fixed version. For sblim-cmpi-sysfs-test version 1.1.9, update to a fixed version. For sblim-cmpi-syslog-test version 0.7.11, update to a fixed version. For sblim-cmpi-nfsv3-test version 1.0.14, update to a fixed version. For sblim-cmpi-nfsv4-test version 1.0.12, update to a fixed version. For sblim-cmpi-params-test version 1.2.6, update to a fixed version. For sblim-gather-test version 2.1.2, update to a fixed version. For sblim-gather-devel version 2.1.2, update to a fixed version. For sblim-testsuite version 1.2.4, update to a fixed version. For sblim-tools-libra-devel version 0.2.3, update to a fixed version. For sblim version 1, update to a fixed version. For sblim version 1-31.el5 2.1, update to a fixed version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2015-06882
BDU:2015-06883
BDU:2015-06884
BDU:2015-06885
BDU:2015-06886
BDU:2015-06887
BDU:2015-06888
BDU:2015-06889
BDU:2015-06890
BDU:2015-06891
BDU:2015-06892
BDU:2015-06893
BDU:2015-06894
BDU:2015-06895
BDU:2015-06896
BDU:2015-06897
BDU:2015-06898
BDU:2015-06899
BDU:2015-06900
BDU:2015-06901
BDU:2015-06902
BDU:2015-06903
BDU:2015-06904
BDU:2015-06905
BDU:2015-06906
BDU:2015-06907
BDU:2015-06908
BDU:2015-08412
BDU:2015-08413
BDU:2015-08414
BDU:2015-08415
BDU:2015-08416
BDU:2015-08417
BDU:2015-08418
BDU:2015-08419
BDU:2015-08420
BDU:2015-08421
BDU:2015-08422
BDU:2015-08423
BDU:2015-08424
BDU:2015-08425
BDU:2015-08426
BDU:2015-08427
BDU:2015-08428
BDU:2015-08429
BDU:2015-08430
BDU:2015-08431
BDU:2015-08432
BDU:2015-08433
BDU:2015-08434
BDU:2015-08435
BDU:2015-08436
BDU:2015-08437
BDU:2015-08438
CVE-2008-1951
RHSA-2008:0497
RHSA-2008_0497

Affected Products

Red Hat
Libc.So
Sblim
Sblim-Cmpi-Base-Devel
Sblim-Cmpi-Base-Test
Sblim-Cmpi-Dns-Devel
Sblim-Cmpi-Dns-Test
Sblim-Cmpi-Fsvol-Devel
Sblim-Cmpi-Fsvol-Test
Sblim-Cmpi-Network-Devel
Sblim-Cmpi-Network-Test
Sblim-Cmpi-Nfsv3-Test
Sblim-Cmpi-Nfsv4-Test
Sblim-Cmpi-Params-Test
Sblim-Cmpi-Samba-Devel
Sblim-Cmpi-Samba-Test
Sblim-Cmpi-Sysfs-Test
Sblim-Cmpi-Syslog-Test
Sblim-Gather-Devel
Sblim-Gather-Test
Sblim-Testsuite
Sblim-Tools-Libra-Devel
Tog-Pegasus