Release date:
Updated on:
Affected Systems:
Fwsnort 1.6.3
Fwsnort
Unaffected system:
Fwsnort 1.6.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65341
CVE (CAN) ID: CVE-2014-0039
Fwsnort is a perl script that converts Snort rules to the same iptables rules.
In versions earlier than fwsnort 1.6.4, a suspicious search PATH Vulnerability exists during non-root operation, allowing local users to execute arbitrary code using the trojan fwsnort. conf in the current working directory.
<* Source: Murray McAllister
Link: http://osvdb.org/102822
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Fwsnort
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cipherdyne.org/fwsnort/
Https://github.com/mrash/fwsnort/commit/fa977453120cc48e1654f373311f9cac468d3348