Gentoo Archives: gentoo-announce

From: Sean Amoss <ackle@g.o>
To: gentoo-announce@l.g.o
Cc: buqtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201201-07 ] NX Server Free Edition, NX Node: Privilege escalation
Date: Mon, 23 Jan 2012 12:16:22
Message-Id: 4F1D4E9B.2070609@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201201-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: NX Server Free Edition, NX Node: Privilege escalation
9 Date: January 23, 2012
10 Bugs: #378345
11 ID: 201201-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 An unspecified vulnerability in NX Server Free Edition and NX Node
19 could allow local attackers to gain root privileges.
20
21 Background
22 ==========
23
24 NX Server Free Edition is a remote display technology by No Machine. NX
25 Node provides the shared components for NX Server.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-misc/nxserver-freeedition
34 < 3.5.0.5 >= 3.5.0.5
35 2 net-misc/nxnode < 3.5.0.4 >= 3.5.0.4
36 -------------------------------------------------------------------
37 2 affected packages
38
39 Description
40 ===========
41
42 NX Server Free Edition and NX Node use nxconfigure.sh, a setuid script
43 containing an unspecified vulnerability.
44
45 Impact
46 ======
47
48 A local attacker could gain escalated privileges.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All NX Server Free Edition users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot -v ">=net-misc/nxserver-freeedition-3.5.0.5"
62
63 All NX Node users should upgrade to the latest version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose ">=net-misc/nxnode-3.5.0.4"
67
68 NOTE: This is a legacy GLSA. Updates for all affected architectures are
69 available since August 23, 2011. It is likely that your system is
70 already no longer affected by this issue.
71
72 References
73 ==========
74
75 [ 1 ] CVE-2011-3977
76 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3977
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-201201-07.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users' machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 https://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2012 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature