Secunia Logo
Netsikker nu! 2008
 
SUSE update for permissions
Secunia Advisory: SA17290
Release Date: 2005-10-24
Popularity: 6,538 views

Critical:
Less critical
Impact: Security Bypass
Where: Local system
Solution Status: Vendor Patch

OS:SuSE Linux 9.0
SuSE Linux 9.1
SUSE Linux 9.2
SUSE Linux 9.3
SuSE Linux Desktop 1.x
SuSE Linux Enterprise Server 8
SUSE Linux Enterprise Server 9
UnitedLinux 1.0

Subscribe: Instant alerts on relevant vulnerabilities


Description:
SUSE has issued an update for permissions. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.

The vulnerability is caused due to the way "chkstat" tries to prevent symlink attacks by not changing the permissions of files that has a hardlink count of more than one. This can be bypassed by creating a hardlink to the targeted file. When the file has been deleted and replaced by a new one by its owner, the hardlink count of the file created by the malicious user will decrease to one, thus allowing the permissions of the targeted file to be changed.

Solution:
Apply updated packages.

-- x86 Platform --

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda...6/permissions-2005.10.20-0.1.i586.rpm
216afa8469276198015e5fff177580d2

SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/upda...6/permissions-2005.10.20-0.1.i586.rpm
3d61d27c7bf81889a321972ac12dcaab

SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/upda...6/permissions-2005.10.20-0.2.i586.rpm
72d9a0b5b0b750fb656aa54eb7c6ebdd

SuSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/upda...586/permissions-2005.10.20-3.i586.rpm
cf8c022048e93fc6d159913ad7824e6a
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/xmcd-3.0.2-552.i586.rpm
f3e82cf342c45ab46fca16c98587b22d

-- x86-64 Platform --

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda...permissions-2005.10.20-0.1.x86_64.rpm
0d11d64965eee2cefeb56edfe258fee4

SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/upda...permissions-2005.10.20-0.1.x86_64.rpm
4f2373ed4a93e3974b919e595a9490b7

SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/up...permissions-2005.10.20-0.2.x86_64.rpm
3ca12f4aae9b7a1b484e6a0e4f8f658d

SuSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/up...4/permissions-2005.10.20-3.x86_64.rpm
853503b8868c1d2a34d05aaf6824cf83
ftp://ftp.suse.com/pub/suse/x86_64/up.../rpm/x86_64/xmcd-3.0.2-552.x86_64.rpm
fd95ac5dd3980af5308abe7062849149

-- Sources --

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda...rc/permissions-2005.10.20-0.1.src.rpm
0a856cadf3b65db9434f20203413aba3

SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/upda...rc/permissions-2005.10.20-0.1.src.rpm
57c3240513c9861634e79547df4f8cf0

SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/upda...rc/permissions-2005.10.20-0.2.src.rpm
b47b5e76f759227d325a33dbbcb5ae96
ftp://ftp.suse.com/pub/suse/x86_64/up...rc/permissions-2005.10.20-0.2.src.rpm
f98fa35639b7d118e6aed1ecb99c4cbb

SuSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../src/permissions-2005.10.20-3.src.rpm
8fa2759f6d2012aee4571e5830ea26eb
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/src/xmcd-3.0.2-552.src.rpm
44f64e89f871fd07bd6291d88277b327
ftp://ftp.suse.com/pub/suse/x86_64/up.../src/permissions-2005.10.20-3.src.rpm
48857a183ff120bc39ebb280eaca8764
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/src/xmcd-3.0.2-552.src.rpm
9e961bdfaf2c935857eb86bd64b74c83

Provided and/or discovered by:
The vendor credits Stefan Nordhausen.

Original Advisory:
http://lists.suse.com/archive/suse-security-announce/2005-Oct/0008.html


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB Avatar Script Insertion Vulnerability // 41 views
2. phpBB Avatar Functions Information Disclosure and Deletion // 37 views
3. CUPS Multiple Vulnerabilities // 37 views
4. Sun Java System Web Proxy Server FTP Subsystem Buffer Overflow // 37 views
5. CA ARCserve Backup Multiple Vulnerabilities // 36 views
6. ScriptsEz Easy Image Downloader "id" File Disclosure Vulnerability // 34 views
7. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities // 34 views
8. phpBB reveals user IPs // 28 views
9. phpBB Cross Site Scripting and Unspecified Vulnerabilities // 27 views
10. FUJITSU Interstage Products Apache Tomcat Security Bypass // 26 views