GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Jan 23, 2012 1:26 pm Post subject: [ GLSA 201201-07 ] NX Server Free Edition, NX Node: Privileg |
|
|
Gentoo Linux Security Advisory
Title: NX Server Free Edition, NX Node: Privilege escalation (GLSA 201201-07)
Severity: high
Exploitable: local
Date: January 23, 2012
Bug(s): #378345
ID: 201201-07
Synopsis
An unspecified vulnerability in NX Server Free Edition and NX Node
could allow local attackers to gain root privileges.
Background
NX Server Free Edition is a remote display technology by No Machine. NX
Node provides the shared components for NX Server.
Affected Packages
Package: net-misc/nxserver-freeedition
Vulnerable: < 3.5.0.5
Unaffected: >= 3.5.0.5
Architectures: All supported architectures
Package: net-misc/nxnode
Vulnerable: < 3.5.0.4
Unaffected: >= 3.5.0.4
Architectures: All supported architectures
Description
NX Server Free Edition and NX Node use nxconfigure.sh, a setuid script
containing an unspecified vulnerability.
Impact
A local attacker could gain escalated privileges.
Workaround
There is no known workaround at this time.
Resolution
All NX Server Free Edition users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=net-misc/nxserver-freeedition-3.5.0.5"
| All NX Node users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/nxnode-3.5.0.4"
| NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since August 23, 2011. It is likely that your system is already
no longer affected by this issue.
References
CVE-2011-3977
|
|