Bug 13813

Summary: [CVE 21] subscription-manager 1.9.6 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: RESOLVED NOTABUG QA Contact: ROSA Linux Bugs <bugs>
Severity: critical    
Priority: Highest CC: a.proklov, e.kosachev, m.novosyolov, s.matveev, v.potapov, y.tumanov
Version: All   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2017-2663, CVE-2023-3899,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-10-18 20:06:27 MSK
Please patch CVEs for package subscription-manager version 1.9.6
  
INFO (CVEs are): subscription-manager 1.9.6
 cves found
CVE-2017-2663
Desc: It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
Link: https://nvd.nist.gov/vuln/detail/CVE-2017-2663
Severity: HIGH
CVE-2023-3899
Desc: A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.
Link: https://nvd.nist.gov/vuln/detail/CVE-2023-3899
Severity: HIGH
Comment 1 Vladimir Potapov 2023-10-20 11:41:58 MSK
*** Bug 13945 has been marked as a duplicate of this bug. ***
Comment 2 Aleksandr Proklov 2023-10-26 03:30:54 MSK
У нас в репах версия 1.29.35 причем в контрибе!

https://abf.io/import/subscription-manager/blob/rosa2021.1/subscription-manager.spec
Comment 3 Yury 2023-10-27 21:09:21 MSK
Надо перетащить сюда
r"https://abf-downloads.rosalinux.ru/rosa2021.1/repository/SRPMS/main/release/"
Comment 4 Aleksandr Proklov 2023-10-28 06:35:11 MSK
по поводу переноса решайте с Михаилом.
Comment 5 Yury 2023-10-31 16:40:36 MSK
(In reply to Aleksandr from comment #4)
> по поводу переноса решайте с Михаилом.

Миша! АУ!
Comment 6 Mikhail Novosyolov 2023-10-31 16:41:53 MSK
Не нужно ничего переносить, пакет не нужен в main, он вообще не нужен. Пусть в контрибе лежит.  RESOLVED NOTABUG.
Comment 7 Yury 2023-10-31 16:43:08 MSK
secteam_verified