Bug 440275 (CVE-2008-1628) - CVE-2008-1628 audit: audit_log_user_command() Buffer Overflow
Summary: CVE-2008-1628 audit: audit_log_user_command() Buffer Overflow
Alias: CVE-2008-1628
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 438840 438844
TreeView+ depends on / blocked
Reported: 2008-04-02 15:52 UTC by Tomas Hoger
Modified: 2021-11-12 19:49 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2008-04-04 07:50:40 UTC

Attachments (Terms of Use)

Description Tomas Hoger 2008-04-02 15:52:21 UTC
Secunia advisory SA29617:

A vulnerability has been reported in Linux Audit, which potentially can be
exploited by malicious, local users to gain escalated privileges.

The vulnerability is caused due to a boundary error within the
"audit_log_user_command()" function in lib/audit_logging.c. This can be
exploited to cause a stack-based buffer overflow via an overly long "command"
argument and potentially execute arbitrary code with the privileges of the
application using libaudit.

The vulnerability is reported in versions prior to 1.7.


Comment 5 Tomas Hoger 2008-04-03 08:25:39 UTC
Further clarification from Steve Grubb:

Vulnerable function audit_log_user_command() was added in audit 1.4, hence
problem exists in Red Hat Enterprise Linux 5.1 and Fedora 7 and later.

However, the only application that currently known to use this interface is
sudo, and only in version currently in Fedora Rawhide/devel.  No application in
Red Hat Enterprise Linux 5.1 uses this audit function and is affected by this

Additionally, this buffer overflow is caught by FORTIFY_SOURCE, so the privilege
escalation is not possible, this only can cause an application crash.  Crash of
sudo is not considered a security issue.

Due to this, this issue will not be treated as security sensitive and will be
addressed in updated audit packages in Red Hat Enterprise Linux 5.2 as
non-security bug fix.

Comment 9 Fedora Update System 2008-04-09 05:20:53 UTC
audit-1.6.8-4.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.