SB2015031103 - Security restrictions bypass in Aconf
Published: March 11, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2015-1419)
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to unknown error related to parsing of "deny_file" option. A remote authenticated attacker can bypass certain security restrictions and gain unauthorized access to protected files on the system.
Successful exploitation of the vulnerability may allow an authenticated attacker to bypass intended security restrictions.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=41ab224df12b8487004a1522b4f671680c082954
- https://git.alpinelinux.org/aports/commit/?id=f0c7d3cb136b30eeeb61a518c2c36fdaab6f1cfa
- https://git.alpinelinux.org/aports/commit/?id=6506b787b579ea013b396e70fab2d1b31d8e250b
- https://git.alpinelinux.org/aports/commit/?id=6bf81f56e8c0b362d9c5ed046d9a8cdb81d5d957
- https://git.alpinelinux.org/aports/commit/?id=6e8169c45ab42a30672742b08a22f18b5c643e72
- https://git.alpinelinux.org/aports/commit/?id=877728e4b39efea18bee758d11611e6692584a63
- https://git.alpinelinux.org/aports/commit/?id=0f34999f6985bddddfd91ed96461e855b8ac37cc
- https://git.alpinelinux.org/aports/commit/?id=2d519469988edc19efb668e43421cf01addae1cd