NX Server Free Edition, NX Node: Privilege escalation
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201201-07 / NX Server NX Node |
| Release Date |
January 23, 2012 |
| Latest Revision |
January 23, 2012: 1 |
| Impact |
high |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/nxserver-freeedition |
<
3.5.0.5 |
>=
3.5.0.5 |
All supported architectures
|
| net-misc/nxnode |
<
3.5.0.4 |
>=
3.5.0.4 |
All supported architectures
|
Related bugreports:
#378345
Synopsis
An unspecified vulnerability in NX Server Free Edition and NX Node
could allow local attackers to gain root privileges.
2.
Impact Information
Background
NX Server Free Edition is a remote display technology by No Machine. NX
Node provides the shared components for NX Server.
Description
NX Server Free Edition and NX Node use nxconfigure.sh, a setuid script
containing an unspecified vulnerability.
Impact
A local attacker could gain escalated privileges.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All NX Server Free Edition users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose
">=net-misc/nxserver-freeedition-3.5.0.5"
|
All NX Node users should upgrade to the latest version:
Code Listing 3.2: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/nxnode-3.5.0.4"
|
NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since August 23, 2011. It is likely that your system is already
no longer affected by this issue.
4.
References
|