Red Hat Enterprise Linux: Updated liberation-fonts package that fixes one bug is now available for Red Hat
Enterprise Linux 7.
Category Archives: Redhat
Redhat
RHBA-2015:1501-1: cronie bug fix and enhancement update
Red Hat Enterprise Linux: Updated cronie packages that fix two bugs and add one enhancement are now
available for Red Hat Enterprise Linux 7.
RHBA-2015:1491-1: Red Hat OpenShift Enterprise 2.1 package dependency update for RHEL 6.7
Red Hat Enterprise Linux: Updated packages are now available for Red Hat OpenShift Enterprise release 2.1.
These packages are required to avoid dependency issues with the base channel for
Red Hat Enterprise Linux 6.7.
RHBA-2015:1492-1: Red Hat OpenShift Enterprise 2.2 package dependency update for RHEL 6.7
Red Hat Enterprise Linux: Updated packages are now available for Red Hat OpenShift Enterprise release 2.2.
These packages are required to avoid dependency issues with the base channel for
Red Hat Enterprise Linux 6.7.
RHBA-2015:1490-1: Red Hat OpenShift Enterprise 2.0 package dependency update for RHEL 6.7
Red Hat Enterprise Linux: Updated packages are now available for Red Hat OpenShift Enterprise release 2.0.
These packages are required to avoid dependency issues with the base channel for
Red Hat Enterprise Linux 6.7.
RHSA-2015:1488-1: Critical: java-1.7.0-ibm security update
Red Hat Enterprise Linux: Updated java-1.7.0-ibm packages that fix several security issues are now
available for Red Hat Enterprise Linux 5 Supplementary.
Red Hat Product Security has rated this update as having Critical security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-1931, CVE-2015-2590, CVE-2015-2601, CVE-2015-2613, CVE-2015-2619, CVE-2015-2621, CVE-2015-2625, CVE-2015-2632, CVE-2015-2637, CVE-2015-2638, CVE-2015-2664, CVE-2015-4000, CVE-2015-4729, CVE-2015-4731, CVE-2015-4732, CVE-2015-4733, CVE-2015-4736, CVE-2015-4748, CVE-2015-4749, CVE-2015-4760
RHSA-2015:1482-1: Important: libuser security update
Red Hat Enterprise Linux: Updated libuser packages that fix two security issues are now available for
Red Hat Enterprise Linux 6.
Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-3245, CVE-2015-3246
RHSA-2015:1483-1: Important: libuser security update
Red Hat Enterprise Linux: Updated libuser packages that fix two security issues are now available for
Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-3245, CVE-2015-3246
RHBA-2015:1489-1: fix dependency issue with python-rhsm
Red Hat Enterprise Linux: Updated python-rhsm packages that fix one bug are now available for RHN Tools
Channel for Red Hat Enterprise Linux 5.
libuser vulnerabilities
Updated 2015-07-24 @ 12:33 UTC
It was discovered that the libuser library contains two vulnerabilities which, in combination, allow unprivileged local users to gain root privileges. libuser is a library that provides read and write access to files like /etc/passwd, which constitute the system user and group database. On Red Hat Enterprise Linux it is a central system component.
What is being disclosed today?
Qualys reported two vulnerabilities:
- CVE-2015-3245: The
userhelperprogram allows local users to add linefeeds in the middle of records to/etc/passwd, corrupting the file. - CVE-2015-3246:
libuseruses a non-standard way of updating/etc/passwdand related files. Its locking is incompatible with the rest of the system, and the files are rewritten in place, which means that the system may observe incorrect data.
It turns out that the CVE-2015-3246 vulnerability, by itself or in conjunction with CVE-2015-3245, can be exploited by an unprivileged local user to gain root privileges on an affected system. However, due to the way libuser works, only users who have accounts already listed in /etc/passwd can exploit this vulnerability, and the user needs to supply the account password as part of the attack. These requirements mean that exploitation by accounts listed only in LDAP (or some other NSS data source) or by system accounts without a valid password is not possible. Further analysis showed that the first vulnerability, CVE-2015-3245, is also due to a missing check in libuser. Qualys has disclosed full technical details in their security advisory posted to the oss-security mailing list.
Which system components are affected by these vulnerabilities?
libuser is a library, which means that in order to exploit it, a program which employs it must be used. Ideally, such a program has the following properties:
- It uses
libuser. - It is SUID-root.
- It allows putting almost arbitrary content into
/etc/passwd.
Without the third item, exploitation may still be possible, but it will be much more difficult. If the program is not SUID-root, a user will not have unlimited attempts to exploit the race condition. A survey of programs processing /etc/passwd and related files presents this picture:
passwdis SUID-root, but it uses PAM to change the password, which has custom code to modify/etc/passwdnot affected by the race condition. The account locking functionality inpasswddoes uselibuser, but it is restricted toroot.chshfromutil-linuxis SUID-root and useslibuserto change/etc/passwd(the latter depending on howutil-linuxwas compiled), but it has fairly strict filters controlling what users can put into these files.lpasswd,lchfn,lchshand related utilities fromlibuserare not SUID-root.userhelper(in theusermodepackage) andchfn(in the util-linux package) have all three qualifications:libuser-based, SUID-root, and lack of filters.
This is why userhelper and chfn are plausible targets for exploitation, and other programs such as passwd and chsh are not.
How can these vulnerabilities be addressed?
System administrators can apply updates from your operating system vendor. Details of affected Red Hat products and security advisories are available on the knowledge base article on the Red Hat Customer Portal. This security update will change libuser to apply additional checks to the values written to the user and group files (so that injecting newlines is no longer possible), and replaces the locking and file update code to follow the same procedures as the rest of the system. The first change is sufficient to prevent newline injection with userhelper as well, which means that only libuser needs to be updated. If software updates are not available or cannot be applied, it is possible to block access to the vulnerable functionality with a PAM configuration change. System administrators can edit the files /etc/pam.d/chfn and /etc/pam.d/chsh and block access to non-root users by using pam_warn (for logging) and pam_deny:
#%PAM-1.0 auth sufficient pam_rootok.so auth required pam_warn.so auth required pam_deny.so auth include system-auth account include system-auth password include system-auth session include system-auth
This will prevent users from changing their login shells and their GECOS field. userhelper identifies itself to PAM as “chfn”, which means this change is effective for this program as well.
Acknowledgements
Red Hat would like to thank Qualys for reporting these vulnerabilities.
Update (2015-07-24): Clarified that chfn is affected as well and linked to Qualys security advisory.
Product
Red Hat Enterprise Linux