Debian DSA-2212-1 : tmux - privilege escalation

medium Nessus Plugin ID 53324

Synopsis

The remote Debian host is missing a security-related update.

Description

Daniel Danner discovered that tmux, a terminal multiplexer, is not properly dropping group privileges. Due to a patch introduced by Debian, when invoked with the -S option, tmux is not dropping permissions obtained through its setgid installation.

The oldstable distribution (lenny) is not affected by this problem, as it does not include tmux.

Solution

Upgrade the tmux packages.

For the stable distribution (squeeze), this problem has been fixed in version 1.3-2+squeeze1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=620304

https://packages.debian.org/source/squeeze/tmux

https://www.debian.org/security/2011/dsa-2212

Plugin Details

Severity: Medium

ID: 53324

File Name: debian_DSA-2212.nasl

Version: 1.11

Type: local

Agent: unix

Published: 4/8/2011

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:tmux, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 4/7/2011

Reference Information

CVE: CVE-2011-1496

DSA: 2212