Samhain update code buffer overflow
| samhain-update-bo (18000) |
Description:
Samhain is vulnerable to a buffer overflow in the database update code, caused by improper bounds checking of user-supplied input. By using the -t update command line option, a local attacker could overflow a buffer and execute arbitrary code on the system with privileges of the Samhain process, once a malicious directory is checked.
Platforms Affected:
- samhain design labs, Samhain 1.8.9 - 2.0.1
Remedy:
Upgrade to the latest version of Samhain (2.0.2 or later), available from the Samhain Download Web page. See References.
Consequences:
Gain Access
References:
- Samhain Download Web page, The SAMHAIN file integrity / intrusion detection system at http://la-samhna.de/samhain/s_download.html.
- Samhain Web page, The SAMHAIN file integrity / intrusion detection system at http://la-samhna.de/samhain/index.html.
- BID-11635: Samhain Labs Samhain Database Update Local Heap Overflow Vulnerability
- CVE-2004-2409: Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode (-t update), might allow attackers to execute arbitrary code.
- CVE-2004-2410: Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of service (null pointer dereference).
- OSVDB ID: 11525: samhain sh_hash_compdata() Function Local Overflow
- OSVDB ID: 11594: samhain sh_hash_compdata() Function NULL Pointer Dereference DoS
- SA13130: Samhain Database Update Code Buffer Overflow Vulnerability
- SECTRACK ID: 1012142: samhain sh_hash_compdata() Buffer Overflow May Let Local Users Gain Elevated Privileges
Reported:
Nov 09, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
