SB2017052507 - Multiple vulnerabilities in Trend Micro ServerProtect for Linux
Published: May 25, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Cross-site scripting (CVE-ID: CVE-2017-9037)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability is caused by incorrect filtration of input data passed via certain parameters of the notification.cgi script. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
2) Cross-site request forgery (CVE-ID: CVE-2017-9033)
The vulnerability allows a remote user to perform CSRF attack.The weakness exists due to insufficient checking of the sent requests. A remote attacker can trick the victim into loading of specially crafted HTML, get access to the affected system and modify information on the target system.
3) Privilege escalation (CVE-ID: CVE-2017-9036)
The disclosed vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to improper security restrictions set on the quarantine directory by the affected software. A local attacker can write an arbitrary file to any location on the file system and gain root privileges.
Successful exploitation of this vulnerability results in privilege escalation.
4) Remote code execution (CVE-ID: CVE-2017-9035)
The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure update method via HTTP without certificate validation. A remote authenticated attacker can modify data in transit to cause the target system to execute arbitrary code.
Successful exploitation of this vulnerability may result in system compromise.
5) Remote code execution (CVE-ID: CVE-2017-9034)
The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure update method without file certificate validation. A remote authenticated attacker can modify data in transit to cause the target system to install and execute arbitrary code.
Successful exploitation of this vulnerability may result in system compromise.
6) Cross-site scripting (CVE-ID: CVE-2017-9032)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability is caused by incorrect filtration of input data passed via certain parameters of the log_management.cgi. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
Install update from vendor's website.