Bug 885205 (CVE-2014-4701) - VUL-0: CVE-2014-4701: nagios-plugins: check_dhcp Arbitrary Option File
Summary: VUL-0: CVE-2014-4701: nagios-plugins: check_dhcp Arbitrary Option File
Status: RESOLVED FIXED
Alias: CVE-2014-4701
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Martin Caj
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/103106/
Whiteboard: maint:released:sle11-sp3:59255 CVSSv2...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-01 08:15 UTC by Victor Pereira
Modified: 2016-09-08 20:24 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-07-01 08:15:13 UTC
CVE-2014-4701

It was reported that check_dhcp plugin allow local unprivileged user to read parts of INI
config files belonging to root on a local system. It could allow an attacker to obtain sensitive information like passwords that should only be accessible by root user.
The vulnerability is due to check_dhcp plugin having Root SUID permissions and inappropriate access control when reading user provided config file (through --extra-opts= option).

As stated in nagios-plugins-README.SuSE-check_dhcpm SUSE doesn't set the setuid bit as default. Therefore we aren't affected.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1098531
http://seclists.org/fulldisclosure/2014/May/74
Comment 1 Swamp Workflow Management 2014-07-01 22:00:17 UTC
bugbot adjusting priority
Comment 2 Lars Vogdt 2014-07-31 16:43:30 UTC
@Martin: as I'm on vacation, can you please take a look?
Comment 5 SMASH SMASH 2014-10-01 22:50:08 UTC
Affected packages:

SLE-11-SP3: nagios-plugins
SLE-11-SP3-PRODUCTS: nagios-plugins
SLE-11-SP3-UPTU: nagios-plugins
Comment 6 Swamp Workflow Management 2014-11-03 23:04:57 UTC
SUSE-SU-2014:1352-1: An update that fixes two vulnerabilities is now available.

Category: security (low)
Bug References: 885205,885207
CVE References: CVE-2014-4701,CVE-2014-4702
Sources used:
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    nagios-plugins-1.4.16-0.13.1
SUSE Linux Enterprise Server 11 SP3 (src):    nagios-plugins-1.4.16-0.13.1
Comment 7 Victor Pereira 2014-12-16 09:10:56 UTC
released