Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Ubuntu 14.10 USN-2579-1: Critical Autofs Privilege Escalation

Ubuntu Large Esm H500
autofs could be made to run programs as an administrator if program maps were configured.
=========================================================================Ubuntu Security Notice USN-2579-1
April 27, 2015

autofs vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.10

Summary:

autofs could be made to run programs as an administrator if program maps
were configured.

Software Description:
- autofs: kernel-based automounter for Linux

Details:

It was discovered that autofs incorrectly filtered environment variables
when using program maps. When program maps were configured, a local user
could use this issue to escalate privileges.

This update changes the default behaviour by adding a prefix to environment
variables. Sites using program maps will need to adapt to the new variable
names, or revert to the previous names by using a new configuration option
called FORCE_STANDARD_PROGRAM_MAP_ENV.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
  autofs                          5.0.8-1ubuntu1.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2579-1
  CVE-2014-8169

Package Information:
  https://launchpad.net/ubuntu/+source/autofs/5.0.8-1ubuntu1.1


Ubuntu 14.10 USN-2579-1: Critical Autofs Privilege Escalation

ubuntu
Calendar Grey April 27, 2015
Dist Ubuntu Esm H88
A vulnerability in autofs may lead to privilege escalation due to misconfigured program maps within the Ubuntu 14.10 environment.
autofs could be made to run programs as an administrator if program maps were configured.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: autofs 5.0.8-1ubuntu1.1 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2579-1

CVE-2014-8169

Severity
critical
Lowest
Low
Medium
High
Critical

April 27, 2015

Package Information

https://launchpad.net/ubuntu/+source/autofs/5.0.8-1ubuntu1.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here