Feeds

Sophos pulls out spade, fills in holes in Web Appliance

Uproots root privilege route, covers it over

Secure remote control for conventional and virtual desktops

Sophos has pulled out the weeds in its web-scanning software after Core Security identified multiple holes in its Web Protection Appliance versions 3.8.0, 3.8.13 and 3.7.9 and earlier.

The Core Security advisory states that if a remote attacker can gain access to the appliance's web administrator interface, the attacker could execute arbitrary commands and gain root privileges.

Acknowledging the issue to The Register, Sophos advised that it had not observed any exploits of the vulnerability in the wild.

The issue arises via a slip in a Perl script, as the advisory states:

[T]he invoked /opt/ws/bin/sblistpack Perl script itself is vulnerable to OS command injection, because its get_referers() function doesn't escape the first argument of the script before using it within a string that will be executed as a command by using backticks.

This opens a vulnerability in which a POST parameter allows the attacker to execute OS commands on the appliance, with the privileges of the operating system user – in this case, "spiderman".

To get from spiderman's OS user privileges to root privileges, the Core Security testers then located a Perl command which runs with root privileges, and which also had an escaping error. Core Security points out that the script “doesn't escape the second argument of the script before using it within a string that will be executed as a command by using backticks. Since it can be run by the spiderman user with the sudo* command, it can be abused to gain root privileges within the appliance.”

Sophos has acknowledged the issue, and Core Security's disclosure, in this notice.

The company says it is now rolling out the update to customers with automatic updating. Customers who have disabled automatic updates can run a manual install. The fix was posted on Friday 6 September. ®

* "sudo", or "superuser do" allows users to run programs with the security privileges of another user.

Secure remote control for conventional and virtual desktops

More from The Register

next story
UK smart meters arrive in 2020. Hackers have ALREADY found a flaw
Energy summit bods warned of free energy bonanza
DRUPAL-OPCALYPSE! Devs say best assume your CMS is owned
SQLi hole was hit hard, fast, and before most admins knew it needed patching
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Mozilla releases geolocating WiFi sniffer for Android
As if the civilians who never change access point passwords will ever opt out of this one
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Mitigating web security risk with SSL certificates
Web-based systems are essential tools for running business processes and delivering services to customers.