CVE-2017-2663
published 2018-07-27CVE-2017-2663: It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.7th percentile
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | subscription-manager | — | — |
| redhat | subscription-manager | < 1.19.4 | 1.19.4 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
subscription-manager: unsafe dbus interface
vendor_redhat·CVSS 8.2
CVE-2017-2663 [HIGH] CWE-270 subscription-manager: unsafe dbus interface
subscription-manager: unsafe dbus interface
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
It was found that subscription-manager's DBus interface let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
Statement: This issue did not affect the versions of subscription-manager as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not inc
GHSA
GHSA-44w6-h8x6-p8h9: It was found that subscription-manager's DBus interface before 1
ghsa_unreviewed·2022-05-13
CVE-2017-2663 [HIGH] GHSA-44w6-h8x6-p8h9: It was found that subscription-manager's DBus interface before 1
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2663 subscription-manager: unsafe dbus interface [fedora-all]
bugzilla·2017-03-21·CVSS 8.2
CVE-2017-2663 [HIGH] CVE-2017-2663 subscription-manager: unsafe dbus interface [fedora-all]
CVE-2017-2663 subscription-manager: unsafe dbus interface [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1434100
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
suggest_reboo
Bugzilla
CVE-2017-2663 subscription-manager: unsafe dbus interface
bugzilla·2017-03-20·CVSS 8.2
CVE-2017-2663 [HIGH] CVE-2017-2663 subscription-manager: unsafe dbus interface
CVE-2017-2663 subscription-manager: unsafe dbus interface
Subscription-manager's new DBus interface allows unprivileged local user to have access to information known to root only, and/or to modify subscription-manager configuration file.
An attacker could use this flaw to escalate its privileges, or to gain access to private information.
Commit enabling the dbus interface (subscription-manager-1.19.0) :
https://github.com/candlepin/subscription-manager/commit/2aa48ef65
Discussion:
Required patches :
* Lock down Facts object to be accessible to root only.
https://github.com/candlepin/subscription-manager/commit/882bb587a
* 1434094: Deny D-BUS Config.Set from non-root
https://github.com/candlepin/subscription-manager/commit/afa0f7afee
---
Created subscription-manager tracking bugs for
http://www.securityfocus.com/bid/97015https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2663https://github.com/candlepin/subscription-manager/commit/2aa48ef65http://www.securityfocus.com/bid/97015https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2663https://github.com/candlepin/subscription-manager/commit/2aa48ef65
2018-07-27
Published