Bug 440275 - (CVE-2008-1628) CVE-2008-1628 audit: audit_log_user_command() Buffer Overflow
CVE-2008-1628 audit: audit_log_user_command() Buffer Overflow
Status: CLOSED NEXTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
source=gentoo,reported=20080401,publi...
: Security
Depends On: 438840 438844
Blocks:
  Show dependency treegraph
 
Reported: 2008-04-02 11:52 EDT by Tomas Hoger
Modified: 2008-04-09 01:20 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-04-04 03:50:40 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Tomas Hoger 2008-04-02 11:52:21 EDT
Secunia advisory SA29617:

A vulnerability has been reported in Linux Audit, which potentially can be
exploited by malicious, local users to gain escalated privileges.

The vulnerability is caused due to a boundary error within the
"audit_log_user_command()" function in lib/audit_logging.c. This can be
exploited to cause a stack-based buffer overflow via an overly long "command"
argument and potentially execute arbitrary code with the privileges of the
application using libaudit.

The vulnerability is reported in versions prior to 1.7.

References:
http://secunia.com/advisories/29617/
http://people.redhat.com/sgrubb/audit/ChangeLog
Comment 5 Tomas Hoger 2008-04-03 04:25:39 EDT
Further clarification from Steve Grubb:

Vulnerable function audit_log_user_command() was added in audit 1.4, hence
problem exists in Red Hat Enterprise Linux 5.1 and Fedora 7 and later.

However, the only application that currently known to use this interface is
sudo, and only in version currently in Fedora Rawhide/devel.  No application in
Red Hat Enterprise Linux 5.1 uses this audit function and is affected by this
problem.

Additionally, this buffer overflow is caught by FORTIFY_SOURCE, so the privilege
escalation is not possible, this only can cause an application crash.  Crash of
sudo is not considered a security issue.

Due to this, this issue will not be treated as security sensitive and will be
addressed in updated audit packages in Red Hat Enterprise Linux 5.2 as
non-security bug fix.
Comment 9 Fedora Update System 2008-04-09 01:20:53 EDT
audit-1.6.8-4.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.