Impact
Severity is low in practice as attacker still required very high privileges to create a process with a forged username.
So it can permits local privilege escalation in environments where the agent runs as root and an attacker controls process usernames.
Patches
Upgrade to GLPI-Agent 1.18
Workarounds
Firstly, a computer won't be affected if sqlplus command is not installed. You can test to run as administrator to run sqlplus -v to check if the command is available.
You can disable databases inventory agent-side by setting no-category = database in configuration.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.
Impact
Severity is low in practice as attacker still required very high privileges to create a process with a forged username.
So it can permits local privilege escalation in environments where the agent runs as root and an attacker controls process usernames.
Patches
Upgrade to GLPI-Agent 1.18
Workarounds
Firstly, a computer won't be affected if
sqlpluscommand is not installed. You can test to run as administrator to runsqlplus -vto check if the command is available.You can disable databases inventory agent-side by setting
no-category = databasein configuration.For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.