Apache CouchDB CVE-2017-12635 and CVE-2017-12636

Bug #1735665 reported by Maik Ihde
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
couchdb (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

The installed CouchDB 1.5.0 in Ubuntu 14.04 LTS is vulnerable to the Attacks as described in https://blog.couchdb.org/2017/11/14/apache-couchdb-cve-2017-12635-and-cve-2017-12636/.

This is a critical flaw combination that allows anyone with access to the couchdb service over the network to create an admin user and start arbitrary processes on the server. And this flaw is actually being used to start "xmrig" Processes for monero mining by attackers in the wild.

lsb_release -rd
Description: Ubuntu 14.04.5 LTS
Release: 14.04

apt-cache policy couchdb
couchdb:
  Installiert: 1.5.0-0ubuntu1
  Installationskandidat: 1.5.0-0ubuntu1
  Versionstabelle:
 *** 1.5.0-0ubuntu1 0
        500 http://archive.ubuntu.com/ubuntu/ trusty/universe amd64 Packages
        100 /var/lib/dpkg/status

(It will surely be the same for the 1.6.x Packages that are included in Xenial (16.04) as well.)

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in couchdb (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for couchdb (Ubuntu) because there has been no activity for 60 days.]

Changed in couchdb (Ubuntu):
status: Incomplete → Expired
information type: Private Security → Public Security
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.