Bug 934507 (CVE-2015-4165) - CVE-2015-4165: elasticsearch: unspecified arbitrary files modification vulnerability
Summary: CVE-2015-4165: elasticsearch: unspecified arbitrary files modification vulner...
Status: RESOLVED WORKSFORME
Alias: CVE-2015-4165
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Forgotten User rQ_j_XsXl2
QA Contact: E-mail List
URL: https://smash.suse.de/issue/117585/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-12 07:54 UTC by Andreas Stieger
Modified: 2017-11-28 12:43 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-06-12 07:54:07 UTC
Courtesy bug for elasticsearch, as found in devel:languages:python and /security:logging:elma:devel. Not in any openSUSE distribution.

All Elasticsearch versions from 1.0.0 to 1.5.2 are vulnerable to an attack that uses Elasticsearch to modify files read and executed by certain other applications.
Upstream bug/commit unknown at the time of writing.

Mitigation:
===========
Users should upgrade to 1.6.0. Alternately, ensure that other applications are not present on the system, or that Elasticsearch cannot write into areas where these applications would read.

External References:

https://www.elastic.co/community/security/


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1230761
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4165
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4165
Comment 1 Swamp Workflow Management 2015-06-12 22:01:53 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2015-11-10 15:53:03 UTC
Hello Maintainer, are you keeping this package up to date?
Comment 3 Andreas Stieger 2017-11-28 12:43:54 UTC
security:logging/elasticsearch is current.
security:logging/elma looks abandoned