PT-2019-12473 · Groonga · Groonga-Httpd
Wolfgang Hotwagner
·
Published
2019-05-02
·
Updated
2019-05-03
·
CVE-2019-11675
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
groonga-httpd version 6.1.5-1
Description
The issue is related to the Debian packaging of the Groonga HTTP server, where the ownership of /var/log/groonga is set to the groonga account. This might allow local users to obtain root access due to unsafe interaction with logrotate. An example exploitation method involves a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash completion.d.
Recommendations
For groonga-httpd version 6.1.5-1, consider changing the ownership of /var/log/groonga to a more secure setting to prevent local users from obtaining root access. As a temporary workaround, restrict access to the logrotate configuration to minimize the risk of exploitation.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Groonga-Httpd