Bug 928972 (CVE-2015-1322) - VUL-0: CVE-2015-1322: NetworkManager,ofono: privilege escalation via path traversal
Summary: VUL-0: CVE-2015-1322: NetworkManager,ofono: privilege escalation via path tra...
Status: RESOLVED INVALID
Alias: CVE-2015-1322
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Mu Lei
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/116336/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-04-28 16:54 UTC by Andreas Stieger
Modified: 2015-04-28 16:56 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-04-28 16:54:56 UTC
Via Ubuntu Security Notice USN-2581-1
http://www.ubuntu.com/usn/usn-2581-1/

> network-manager vulnerability
> ==========================================================================
> 
> A security issue affects these releases of Ubuntu and its derivatives:
> 
> - Ubuntu 15.04
> - Ubuntu 14.10
> - Ubuntu 14.04 LTS
> 
> Summary:
> 
> NetworkManager would allow unintended access to files and modem device
> configuration.
> 
> Software Description:
> - network-manager: Network connection manager
> 
> Details:
> 
> Tavis Ormandy discovered that NetworkManager incorrectly filtered paths
> when requested to read modem device contexts. A local attacker could
> possibly use this issue to bypass privileges and manipulate modem device
> configuration or read arbitrary files.


On LP:

> * SECURITY UPDATE: directory traversal issue resulting in connection
>     modification and possible arbitrary file disclosure (LP: #1449245)
>     - debian/patches/CVE-2015-1322.patch: strip slashes from filename
>       in src/settings/plugins/ofono/plugin.c.
>     - CVE-2015-1322

The bug: https://bugs.launchpad.net/ubuntu/+source/network-manager/+bug/1449245

What is odd:
> Apparently you're not happy with me for discussing local privilege
> escalation on oss-security, so as you requested, here's what appears
> to be a problem in Ubuntu-specific code.

We do not ship src/settings/plugins/ofono/plugin.c.

References:
https://bugs.launchpad.net/ubuntu/+source/network-manager/+bug/1449245
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1322
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1322.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1322
Comment 1 Andreas Stieger 2015-04-28 16:56:53 UTC
Code not found in NetworkManager or ofono code, SLE or openSUSE.
Fixing as Ubuntu specific.