RHEL 2.1 : Canna (RHSA-2002:261)

high Nessus Plugin ID 12336

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The Canna server, used for Japanese character input, has two security vulnerabilities including an exploitable buffer overflow that allows a local user to gain 'bin' user privileges. Updated packages for Red Hat Linux Advanced Server are available.

[Updated 13 Jan 2003] Added fixed packages for the Itanium (IA64) architecture.

[Updated 06 Feb 2003] Added fixed packages for Advanced Workstation 2.1

Canna is a kana-kanji conversion server which is necessary for Japanese language character input.

A buffer overflow bug in the Canna server up to and including version 3.5b2 allows a local user to gain the privileges of the user 'bin' which can lead to further exploits. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2002-1158 to this issue.

In addition, it was discovered that request validation was lacking in Canna server versions 3.6 and earlier. A malicious remote user could exploit this vulnerability to leak information or cause a denial of service attack. (CVE-2002-1159)

Red Hat Linux Advanced Server ships with a Canna package vulnerable to these issues; however, the package is normally only installed when Japanese language support is selected during installation.

All users of Canna are advised to upgrade to these errata packages which contain a backported security fix and are not vulnerable to this issue.

Red Hat would like to thank hsj and AIDA Shinra for the responsible disclosure of these issues.

Solution

Update the affected Canna, Canna-devel and / or Canna-libs packages.

See Also

https://access.redhat.com/security/cve/cve-2002-1158

https://access.redhat.com/security/cve/cve-2002-1159

http://canna.osdn.jp/sec/Canna-2002-01.txt

https://access.redhat.com/errata/RHSA-2002:261

Plugin Details

Severity: High

ID: 12336

File Name: redhat-RHSA-2002-261.nasl

Version: 1.23

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:canna, p-cpe:/a:redhat:enterprise_linux:canna-devel, p-cpe:/a:redhat:enterprise_linux:canna-libs, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 2/5/2003

Vulnerability Publication Date: 12/18/2002

Reference Information

CVE: CVE-2002-1158, CVE-2002-1159

RHSA: 2002:261