CVE-2014-3486: Medium severity red hat cloudforms management engine vulnerability
Kurt Seifried of Red Hat Product Security reports:
======================================== ./lib/util/MiqSshUtilV1.rb def shellexec(cmd, doneStr=nil, shell=@shell) if shell # Writing to a temp remote script to handle cases where the cmd string is # too long and is truncated. tempremotescript = "/var/tmp/miq-#{Time.now.toi}.sh" self.exec("echo \"#{cmd}\" > #{tempremotescript}") self.exec("chmod 700 #{tempremotescript}") out = shell.sendcommand(tempremotescript) self.exec("rm -f #{tempremotescript}") @status = out.status msg = out.stdout
# Check if the first output return references the remote script and remove it. msgs = msg.split("\n") msg = msgs[1..-1].join("\n") if msgs[0].include?(tempremotescript)
raise "#{msg}" unless doneStr.nil? || msg.include?(doneStr) return msg else return self.exec(cmd, doneStr) end end ======================================== ./lib/util/MiqSshUtilV2.rb def tempcmdfile(cmd) tempremotescript = "/var/tmp/miq-#{Time.now.toi}.sh" self.exec("echo \"#{cmd}\" > #{tempremotescript}") remotecmd = "chmod 700 #{tempremotescript}; #{tempremotescript}; rm -f #{tempremotescript}" yield(remotecmd) end ======================================== Time.now.toi = 1412123123 setup a file and a few hundred/thousand symlinks and you can cover an hour easily.
Between the
self.exec("echo \"#{cmd}\" > #{tempremotescript}") self.exec("chmod 700 #{tempremotescript}")
an attacker can replace the file, which is then executed as root.
It should use Ruby Tempfile: http://kurt.seifried.org/2012/03/14/creating-temporary-files-securely/
Other sources
The (1) shellexec function in lib/util/MiqSshUtilV1.rb and (2) tempcmdfile function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3486?
CVE-2014-3486 is classified as a medium severity vulnerability.
How do I fix CVE-2014-3486?
To address CVE-2014-3486, update the Red Hat CloudForms Management Engine to the latest version recommended by Red Hat.
What impact does CVE-2014-3486 have on my system?
CVE-2014-3486 may allow an attacker to execute arbitrary commands on a vulnerable system.
Which versions of Red Hat CloudForms Management Engine are affected by CVE-2014-3486?
CVE-2014-3486 affects versions 5.2 to 5.2.4 of the Red Hat CloudForms Management Engine.
Is CVE-2014-3486 a remote code execution vulnerability?
Yes, CVE-2014-3486 can be exploited to facilitate remote code execution on vulnerable systems.