Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2024:3785-1 important: pcp local privilege escalation and updates

suse
Calendar Grey October 30, 2024
Dist Suse Esm H88
Security patches for pcp emphasize severe weaknesses in SUSE offerings, outlining essential remedies and categories of risks.
* bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345

Summary

## This update for pcp fixes the following issues: pcp was updated from version 5.2.5 to version 6.2.0 (jsc#PED-8192, jsc#PED-8389): * Security issues fixed: * CVE-2024-45770: Fixed a symlink attack that allows escalating from the pcp to the root user (bsc#1230552) * CVE-2024-45769: Fixed a heap corruption through metric pmstore operations (bsc#1230551) * CVE-2023-6917: Fixed local privilege escalation from pcp user to root in /usr/libexec/pcp/lib/pmproxy (bsc#1217826) * Major changes: * Add version 3 PCP archive support: instance domain change-deltas, Y2038-safe timestamps, nanosecond-precision timestamps, arbitrary timezones support, 64-bit file offsets used throughout for larger (beyond 2GB) individual volumes * Opt-in using the /etc/pcp.conf PCP_ARCHIVE_VERSION setting

References

* bsc#1217826

* bsc#1222815

* bsc#1230551

* bsc#1230552

* bsc#1231345

* jsc#PED-8192

* jsc#PED-8389

Cross-

* CVE-2023-6917

* CVE-2024-45769

* CVE-2024-45770

CVSS scores:

* CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-45769 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-45770 ( SUSE ): 4.6

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

* CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

* CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products:

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3785-1
Release Date: 2024-10-30T07:56:18Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here