LWN.net Logo

rgmanager: privilege escalation

Package(s):rgmanager CVE #(s):CVE-2010-3389
Created:July 21, 2011 Updated:December 9, 2011
Description: From the Red Hat advisory:

The rgmanager package contains the Red Hat Resource Group Manager, which provides the ability to create and manage high-availability server applications in the event of system downtime.

It was discovered that certain resource agent scripts set the LD_LIBRARY_PATH environment variable to an insecure value containing empty path elements. A local user able to trick a user running those scripts to run them while working from an attacker-writable directory could use this flaw to escalate their privileges via a specially-crafted dynamic library.

Alerts:
Scientific Linux SL-reso-20111206 2011-12-06
Red Hat RHSA-2011:1580-03 2011-12-06
Gentoo 201110-18 2011-10-22
CentOS CESA-2011:1000 2011-09-22
Red Hat RHSA-2011:1000-01 2011-07-21
Scientific Linux SL-rgma-20110721 2011-07-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds