GLSA-200409-17 : SUS: Local root vulnerability

high Nessus Plugin ID 14725

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200409-17 (SUS: Local root vulnerability)

Leon Juranic found a bug in the logging functionality of SUS that can lead to local privilege escalation. A format string vulnerability exists in the log() function due to an incorrect call to the syslog() function.
Impact :

An attacker with local user privileges can potentially exploit this vulnerability to gain root access.
Workaround :

There is no known workaround at this time.

Solution

All SUS users should upgrade to the latest version:
# emerge sync # emerge -pv '>=app-admin/sus-2.0.2-r1' # emerge '>=app-admin/sus-2.0.2-r1'

See Also

http://pdg.uow.edu.au/sus/CHANGES

https://www.securityfocus.com/archive/1/375109/2004-09-11/2004-09-17/0

https://security.gentoo.org/glsa/200409-17

Plugin Details

Severity: High

ID: 14725

File Name: gentoo_GLSA-200409-17.nasl

Version: 1.17

Type: local

Published: 9/15/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:sus, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 9/14/2004

Reference Information

CVE: CVE-2004-1469

GLSA: 200409-17