Research Archives > Security Advisories > AL20111108
eEye Audit ID 2499 Remote Privilege Escalation
Release Date:
11/8/2011 12:00:00 AM
Date Reported:
10/3/2011 12:00:00 AM
Severity:
Moderate
Vendor:
eEye Digital Security
Affected Software:
Retina Network Security Scanner with eEye Digital Security Audits Revision 2406 through Audits Revision 2423.
Overview:
eEye Retina Network Security Scanner audits have the capability to run remote shell scripts in order to determine vulnerable applications. eEye Audit ID 2499 uses find(1) and execute (-exec) when assessing a vulnerability within the Gauntlet Firewall. An attacker who can write an executable file in the portion of the file system searched with the find command may be able to exploit this vulnerability to execute arbitrary code with the privileges provided to Retina to perform the vulnerability scan.
Technical Details:
The eEye Retina Network Security Scanner software executes various audits against target systems to conduct security vulnerability assessment testing. eEye provides audits to help perform security reviews of various operating systems and applications.
Audit ID 2499 ("Gauntlet Firewall For UNIX Buffer Overflow") checks for a vulnerability by examining the program version of Gauntlet Firewall. The version is obtained by searching /usr/local and its subdirectories and executing any files found that match the search criteria. As the audit executes a program based on filename, if an attacker can place an appropriately named executable file within /usr/local, that file will be executed by Retina.
eEye recommends not running Retina with a privileged user unless the system administrator has evaluated the target environment and determined that directory and file permissions are set correctly.
Affected Platforms:
- Solaris
- HP-UX
- IRIX
Shell Script Executed:
find /usr/local -name gauntlet -exec {} -v \
Protection:
- Do not allow unprivileged users write access to /usr/local and its subdirectories on Solaris, HP-UX, and IRIX systems.
- Remove audit 2499 from the scan policy.
- Perform vulnerability scans with unprivileged (non-root) user accounts.
Vendor Status:
eEye Digital Security has issued a security update for this product. This fix is implemented in eEye Digital Security Audits Revision 2424 (released 10/03/2011) and later. The latest audits revision is available for download from the eEye Clients Portal (http://www.eeye.com/clients) or by using the eEye Auto-Updater.
Links:
CERT Advisory VU448051
CVE-2011-3337
Credit:
Michael Rutkowski of Duer Advanced Technology and Aerospace, Inc (DATA) for reporting this vulnerability via CERT
Copyright ©1998-2011 eEye Digital Security
Permission is hereby granted for the redistribution of this alert electronically. It is not to be edited in any way without express consent of eEye. If you wish to reprint the whole or any part of this alert in any other medium excluding electronic medium, please email alert@eEye.com for permission.
Disclaimer
The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are no warranties, implied or express, with regard to this information. In no event shall the author be liable for any direct or indirect damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.