Race condition in File-Path - CVE-2017-6512

 

Race condition in File-Path - CVE-2017-6512

Published: June 5, 2017 / Updated: June 5, 2017


Vulnerability identifier: #VU6900
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6512
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass certain security restrictions.

the vulnerability exists due to a race condition in rmtree() and remove_tree() functions within the File-Path module for Perl. A local user can set a mode on arbitrary files via vectors involving directory-permission loosening logic.

Successful exploitation of the vulnerability may allow an attacker to escalate privileges on the system.

Affected software

File-Path
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Server
openSUSE Leap
Fedora
SUSE Linux Enterprise Module for Packagehub Subpackages
perl-File-Path
perl-base
perl-base-32bit-debuginfo
perl-base-32bit
perl-32bit-debuginfo
perl-doc
perl-debugsource
perl-base-debuginfo
perl
perl-debuginfo
perl-core-DB_File-32bit-debuginfo
perl-core-DB_File-32bit
perl-32bit
perl-core-DB_File-debuginfo
perl-core-DB_File
PowerStore X
PowerStore T
EMC Cloud Tiering Appliance

How to mitigate CVE-2017-6512

Update File::Path module to version 2.13.

perl-File-Path - addressed in versions 2.12-3.fc24, 2.12-366.fc25, 2.12-367.fc26
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
perl-base - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-base-32bit-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-base-32bit - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-32bit-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-doc - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-debugsource - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-base-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.11.1
perl-core-DB_File-32bit-debuginfo - update to 5.26.1-150300.17.11.1
perl-core-DB_File-32bit - update to 5.26.1-150300.17.11.1
perl-32bit - update to 5.26.1-150300.17.11.1
perl-core-DB_File-debuginfo - update to 5.26.1-150300.17.11.1
perl-core-DB_File - update to 5.26.1-150300.17.11.1
EMC Cloud Tiering Appliance - update to 13.2.0.2.31

External References

Related Security Bulletins