GLSA-200704-20 : NAS: Multiple vulnerabilities

critical Nessus Plugin ID 25108

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200704-20 (NAS: Multiple vulnerabilities)

Luigi Auriemma has discovered multiple vulnerabilities in NAS, some of which include a buffer overflow in the function accept_att_local(), an integer overflow in the function ProcAuWriteElement(), and a null pointer error in the function ReadRequestFromClient().
Impact :

An attacker having access to the NAS daemon could send an overly long slave name to the server, leading to the execution of arbitrary code with root privileges. A remote attacker could also send a specially crafted packet containing an invalid client ID, which would crash the server and result in a Denial of Service.
Workaround :

There is no known workaround at this time.

Solution

All NAS users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=media-libs/nas-1.8b'

See Also

https://security.gentoo.org/glsa/200704-20

Plugin Details

Severity: Critical

ID: 25108

File Name: gentoo_GLSA-200704-20.nasl

Version: 1.14

Type: local

Published: 4/30/2007

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:nas, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 4/23/2007

Vulnerability Publication Date: 3/19/2007

Reference Information

CVE: CVE-2007-1543, CVE-2007-1544, CVE-2007-1545, CVE-2007-1546, CVE-2007-1547

GLSA: 200704-20