Incorrect default permissions in rmt-server - CVE-2022-31254

 

Incorrect default permissions in rmt-server - CVE-2022-31254

Published: January 4, 2023


Vulnerability identifier: #VU70668
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31254
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for the "/usr/share/rmt" directory. A local _rmt user can edit the "/usr/share/rmt/.bundle/config" file and execute arbitrary code on the system as root during service startup.


Affected software

rmt-server
rmt-server-debuginfo
rmt-server-config
rmt-server-pubcloud
rmt-server-debugsource
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Realtime Extension
Public Cloud Module
Server Applications Module
openSUSE Leap

How to mitigate CVE-2022-31254

Install updates from vendor's website.

rmt-server - addressed in versions 2.10-150000.3.61.1, 2.10-150100.3.42.1, 2.10-150200.3.29.1, 2.10-150300.3.21.1, 2.10-150400.3.9.1, 2.13-150500.3.3.1
rmt-server-debuginfo - addressed in versions 2.10-150000.3.61.1, 2.10-150100.3.42.1, 2.10-150200.3.29.1, 2.10-150300.3.21.1, 2.10-150400.3.9.1, 2.13-150500.3.3.1
rmt-server-config - addressed in versions 2.10-150000.3.61.1, 2.10-150100.3.42.1, 2.10-150200.3.29.1, 2.10-150300.3.21.1, 2.10-150400.3.9.1, 2.13-150500.3.3.1
rmt-server-pubcloud - addressed in versions 2.10-150100.3.42.1, 2.10-150200.3.29.1, 2.10-150300.3.21.1, 2.10-150400.3.9.1, 2.13-150500.3.3.1
rmt-server-debugsource - addressed in versions 2.10-150200.3.29.1, 2.10-150300.3.21.1, 2.10-150400.3.9.1, 2.13-150500.3.3.1

External References

Related Security Bulletins