Bug 848639 (CVE-2013-4480) - VUL-0: CVE-2013-4480: spacewalk: admin user dialog problem
Summary: VUL-0: CVE-2013-4480: spacewalk: admin user dialog problem
Status: RESOLVED FIXED
Alias: CVE-2013-4480
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P1 - Urgent : Critical
Target Milestone: ---
Deadline: 2013-11-05
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp2:54951
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-01 13:30 UTC by Marcus Meissner
Modified: 2013-11-13 16:41 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2013-11-01 23:00:41 UTC
bugbot adjusting priority
Comment 4 Swamp Workflow Management 2013-11-03 08:42:35 UTC
The SWAMPID for this issue is 54909.
This issue was rated as critical.
Please submit fixed packages until 2013-11-05.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 12 Marcus Meissner 2013-11-06 17:21:41 UTC
Kurt wrote the final CRD: Tuesday Nov 12th, 2013, 11am EST.
Comment 13 Victor Pereira 2013-11-12 16:34:01 UTC
This update fixes an admin user dialog problem in spacewalk. The "add new admin user" functionality didn't get disabled after it was used. So after install/adding a remote attacker could use this flaw to create an administrator user with credentials they specify. This user could then be used to assume control of the Satellite server.

Security Issue reference:

- [CVE-2013-4480](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4480)
Comment 14 Swamp Workflow Management 2013-11-12 18:46:05 UTC
Update released for: spacewalk-java, spacewalk-java-config, spacewalk-java-lib, spacewalk-java-oracle, spacewalk-java-postgresql, spacewalk-java-tests, spacewalk-taskomatic
Products:
SUSE-MANAGER 1.7 (x86_64)