Secunia CSI 5.0
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA39176

SUSE Update for Multiple Packages
Secunia Advisory SA39176
Get alerted and manage the vulnerability life cycle
Free Trial

Release Date 2010-03-31
   
Popularity 1,276 view
Comments 0 comments

Criticality level Highly criticalHighly critical
Impact Security Bypass
Cross Site Scripting
Spoofing
Exposure of system information
Exposure of sensitive information
Privilege escalation
DoS
System access
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
   
Operating System
openSUSE 11.0
openSUSE 11.1
openSUSE 11.2
SUSE Linux Enterprise Server (SLES) 11
SUSE Linux Enterprise Server 9

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2008-6514 CVSS available in Customer Area
CVE-2008-7247 CVSS available in Customer Area
CVE-2009-1299 CVSS available in Customer Area
CVE-2009-2563 CVSS available in Customer Area
CVE-2009-2855 CVSS available in Customer Area
CVE-2009-3553 CVSS available in Customer Area
CVE-2009-4019 CVSS available in Customer Area
CVE-2009-4028 CVSS available in Customer Area
CVE-2009-4030 CVSS available in Customer Area
CVE-2009-4376 CVSS available in Customer Area
CVE-2009-4377 CVSS available in Customer Area
CVE-2009-4484 CVSS available in Customer Area
CVE-2010-0302 CVSS available in Customer Area
CVE-2010-0304 CVSS available in Customer Area
CVE-2010-0308 CVSS available in Customer Area
CVE-2010-0393 CVSS available in Customer Area
CVE-2010-0424 CVSS available in Customer Area
CVE-2010-0547 CVSS available in Customer Area
CVE-2010-0628 CVSS available in Customer Area
CVE-2010-0736 CVSS available in Customer Area
CVE-2010-0926 CVSS available in Customer Area
  

Description

SUSE has issued an update for multiple packages. This fixes a weakness, security issues, and vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated privileges, and by malicious people to conduct spoofing attacks, disclose system and potentially sensitive information, bypass certain security restrictions, cause a DoS, and potentially compromise a vulnerable system.

For more information:
SA30134
SA33077
SA36378
SA37364
SA37372
SA37842
SA38257
SA38364
SA38390
SA38451
SA38454
SA38700
SA38789
SA38895
SA39010

1) A security issue is caused due to MySQL checking the validity of a local path by using a requested table name without extension. This can be exploited to bypass table access restrictions in CREATE TABLE statements via symlink attacks.

This is related to:
SA30134

2) A security issue is caused due to pulseaudio performing chown() and chmod() calls without checking for symbolic links in existing directories. This can be exploited to e.g. change permissions and ownership of arbitrary files via symlink attacks.

3) The "mount.cifs" utility does not properly sanitise certain input, which can be exploited to corrupt the /etc/mtab file.

Successful exploitation requires that "mount.cifs" is setuid root (not setuid root by default).


Solution
Apply updated packages via YaST Online Update or the SUSE FTP server.
Original Advisory
SUSE-SR:2010:007:
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00008.html

Other references
Further details available in Customer Area

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: SUSE Update for Multiple Packages
 
No posts yet

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability