Code Injection in sccache - CVE-2023-1521

 

Code Injection in sccache - CVE-2023-1521

Published: September 5, 2023


Vulnerability identifier: #VU80466
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1521
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the way the server handles compile request. A local user can execute arbitrary code with the privileges of a local sccache server by preloading the code in a shared library passed to LD_PRELOAD.


Affected software

sccache
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
sccache-debuginfo
sccache

How to mitigate CVE-2023-1521

Install updates from vendor's website.

sccache - update to 0.4.0
sccache-debuginfo - addressed in versions 0.4.1~18-150300.7.12.1, 0.4.2~3-150400.3.3.1
sccache - addressed in versions 0.4.1~18-150300.7.12.1, 0.4.2~3-150400.3.3.1

External References

Related Security Bulletins