Debian DSA-1754-1 : roundup - insufficient access checks

medium Nessus Plugin ID 36134

Synopsis

The remote Debian host is missing a security-related update.

Description

It was discovered that roundup, an issue tracker with a command-line, web and email interface, allows users to edit resources in unauthorized ways, including granting themselves admin rights.

This update introduces stricter access checks, actually enforcing the configured permissions and roles. This means that the configuration may need updating. In addition, user registration via the web interface has been disabled; use the program 'roundup-admin' from the command line instead.

Solution

Upgrade the roundup package.

For the old stable distribution (etch), this problem has been fixed in version 1.2.1-10+etch1.

For the stable distribution (lenny), this problem has been fixed in version 1.4.4-4+lenny1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=518768

https://www.debian.org/security/2009/dsa-1754

Plugin Details

Severity: Medium

ID: 36134

File Name: debian_DSA-1754.nasl

Version: 1.14

Type: local

Agent: unix

Published: 4/11/2009

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:roundup, cpe:/o:debian:debian_linux:4.0, cpe:/o:debian:debian_linux:5.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 4/9/2009

Reference Information

CVE: CVE-2009-2737

BID: 34059

CWE: 264

DSA: 1754