Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 15 Oct 2012 15:50:42 -0500
From: Raphael Geissert <geissert@...ian.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2012-2248: isc-dhcp, Debian-specific: build path included in PATH

Hi,

Michael Stapelberg, Tollef Fog Heen, and Michael Biebl discovered that 
dhclient was setting dhclient-script's PATH to one that included a 
subdirectory of the build directory[1].
This issue is caused by the way isc-dhcp is packaged in Debian.

At least two versions of isc-dhcp for the amd64 (x86_64) architecture in 
Debian were found two be setting PATH to a subdirectory of /home/zero79/, 
which would allow a user with such HOME directory to be able to execute code 
as root.

To clarify the bug report: it is not specific to samba or hooks in general, 
PATH is injected in the environment passed to the execve() call that 
executes dhclient-script.

Since this issue doesn't affect the stable release, there won't be a DSA. 
This email is just a heads up.

[1]http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690532

Cheers,
-- 
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.