SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Generic)  >   Star Vendors:   Schilling, J.
(Gentoo Issues Fix) Star Has Unspecified Flaw That May Let Local Users Gain Root Privileges
SecurityTracker Alert ID:  1011196
SecurityTracker URL:  http://securitytracker.com/id/1011196
CVE Reference:   CAN-2004-0850   (Links to External Site)
Updated:  Sep 26 2004
Original Entry Date:  Sep 8 2004
Impact:   Root access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 1.5a09 - 1.5a45
Description:   A vulnerability was reported in Star. A local user may be able to gain root privileges.

The vendor reported that when ssh is used for remote tape access (and the application is configured with set user id 'root' user privileges), there exists a vulnerability in Star that may allow a local user to obtain root privileges.

Impact:   A local user may be able to obtain root access.
Solution:   Gentoo has released a fix and indicates that all star users should upgrade to the latest version:

# emerge sync

# emerge -pv ">=app-arch/star-1.5_alpha46"
# emerge ">=app-arch/star-1.5_alpha46"

Vendor URL:  ftp.berlios.de/pub/schily/star/README (Links to External Site)
Cause:   Not specified
Underlying OS:   Linux (Gentoo)

Message History:   This archive entry is a follow-up to the message listed below.
Sep 8 2004 Star Has Unspecified Flaw That May Let Local Users Gain Root Privileges



 Source Message Contents

Date:  Tue, 7 Sep 2004 23:48:44 +0000
Subject:  [gentoo-announce] [ GLSA 200409-11 ] star: Suid root vulnerability



--cvVnyQ+4j833TQvp
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200409-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: star: Suid root vulnerability
      Date: September 07, 2004
      Bugs: #61797
        ID: 200409-11

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

star contains a suid root vulnerability which could potentially grant
unauthorized root access to an attacker.

Background
==========

star is an enhanced tape archiver, much like tar, that is recognized
for it's speed as well as it's enhanced mt/rmt support.

Affected packages
=================

    -------------------------------------------------------------------
     Package        /      Vulnerable      /                Unaffected
    -------------------------------------------------------------------
  1  app-arch/star     < star-1.5_alpha46          >= star-1.5_alpha46

Description
===========

A suid root vulnerability exists in versions of star that are
configured to use ssh for remote tape access.

Impact
======

Attackers with local user level access could potentially gain root
level access.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All star users should upgrade to the latest version:

    # emerge sync

    # emerge -pv ">=app-arch/star-1.5_alpha46"
    # emerge ">=app-arch/star-1.5_alpha46"

References
==========

  [ 1 ] Star Mailing List Announcement
        https://lists.berlios.de/pipermail/star-users/2004-August/000239.html

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200409-11.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2004 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/1.0

--cvVnyQ+4j833TQvp
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBPkjcJPpRNiftIEYRAgfIAJ9uU0/au2KtJfynTjenGn+nHIwqsACfandU
h8kc2FFmMNGz1Dfdw2yjZkI=
=INQO
-----END PGP SIGNATURE-----

--cvVnyQ+4j833TQvp--

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC