Summary: | security/ossec-hids-server: root escalation via syscheck feature | ||||||
---|---|---|---|---|---|---|---|
Product: | Ports & Packages | Reporter: | Jason Unovitch <junovitch> | ||||
Component: | Individual Port(s) | Assignee: | Brad Davis <brd> | ||||
Status: | Closed FIXED | ||||||
Severity: | Affects Some People | Flags: | bugzilla:
maintainer-feedback?
(brd) |
||||
Priority: | --- | ||||||
Version: | Latest | ||||||
Hardware: | Any | ||||||
OS: | Any | ||||||
Attachments: |
|
Description
Jason Unovitch
2015-06-12 00:47:46 UTC
Created attachment 157656 [details] security/vuxml entry for ossec-hids-* and CVE-2015-3222 Validation: # make validate /bin/sh /usr/ports/security/vuxml/files/tidy.sh "/usr/ports/security/vuxml/files/tidy.xsl" "/usr/ports/security/vuxml/vuln.xml" > "/usr/ports/security/vuxml/vuln.xml.tidy" >>> Validating... /usr/local/bin/xmllint --valid --noout /usr/ports/security/vuxml/vuln.xml >>> Successful. Checking if tidy differs... ... seems okay Checking for space/tab... ... seems okay /usr/local/bin/python2.7 /usr/ports/security/vuxml/files/extra-validation.py /usr/ports/security/vuxml/vuln.xml # env PKG_DBDIR=/usr/ports/security/vuxml pkg audit ossec-hids-server-2.8.2 0 problem(s) in the installed packages found. # env PKG_DBDIR=/usr/ports/security/vuxml pkg audit ossec-hids-server-2.8.1 ossec-hids-server-2.8.1 is vulnerable: security/ossec-hids-* -- root escalation via syscheck feature CVE: CVE-2015-3222 WWW: http://vuxml.FreeBSD.org/freebsd/c470db07-1098-11e5-b6a8-002590263bf5.html 1 problem(s) in the installed packages found. # env PKG_DBDIR=/usr/ports/security/vuxml pkg audit ossec-hids-server-2.7 ossec-hids-server-2.7 is vulnerable: security/ossec-hids-* -- root escalation via syscheck feature CVE: CVE-2015-3222 WWW: http://vuxml.FreeBSD.org/freebsd/c470db07-1098-11e5-b6a8-002590263bf5.html ossec-hids-server-2.7 is vulnerable: security/ossec-hids-* -- root escalation via temp files CVE: CVE-2014-5284 WWW: http://vuxml.FreeBSD.org/freebsd/36858e78-3963-11e4-ad84-000c29f6ae42.html 1 problem(s) in the installed packages found. Thanks for the report. I am looking into it. A commit references this bug: Author: brd Date: Fri Jun 12 14:10:39 UTC 2015 New revision: 389270 URL: https://svnweb.freebsd.org/changeset/ports/389270 Log: Add ossec-hids-* vulnerabilities. PR: 200801 Submitted by: Jason Unovitch <jason.unovitch@gmail.com> Approved by: swills (mentor) Changes: head/security/vuxml/vuln.xml Also committed the 2.8.2 update to the security/ossec-hids-* ports as r389271. |