REDHAT-BUG-1487252: Low severity open-iscsi tcmu-runner vulnerability
A local non-root user with access to the D-Bus system bus can call the CheckConfig method implemented in the tcmu-runner daemon via handlerqcow.so and exploit an information leak by passing in arbitrary filenames to check.
This allows a local user to check for the existence of root owned files, which might enable more serious security issues in combination with other security flaws in a system.
Upstream patch:
https://github.com/open-iscsi/tcmu-runner/commit/8cf8208775022301adaa59c240bb7f93742d1329
References:
http://seclists.org/oss-sec/2017/q3/207
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1487252?
The severity of REDHAT-BUG-1487252 is classified as low.
What is REDHAT-BUG-1487252 about?
REDHAT-BUG-1487252 describes a local information leak vulnerability in the tcmu-runner daemon that can be exploited by non-root users.
How can a local user exploit REDHAT-BUG-1487252?
A local user can exploit REDHAT-BUG-1487252 by using the CheckConfig method in tcmu-runner to check for the existence of root-owned files.
What impact does REDHAT-BUG-1487252 have?
The impact of REDHAT-BUG-1487252 allows unauthorized local users to potentially gain insights into file permissions and the existence of files owned by root.
How do I fix REDHAT-BUG-1487252?
To fix REDHAT-BUG-1487252, it is recommended to update to the latest version of the tcmu-runner that addresses this vulnerability.