zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 8, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 8, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Major Linux Distributions Affected by Root Access Vulnerability
  • ShellTorch Exposes Tens of Thousands of Servers Worldwide to Attacks
  • CloudFlare Firewall and DDoS Prevention Vulnerable to Bypass

Major Linux Distributions Affected by Root Access Vulnerability

A high-severity Linux vulnerability (CVE-2023-4911), known as "Looney Tunables," allows local attackers to obtain root privileges by exploiting a buffer overflow weakness in the GNU C Library's ld[.]so dynamic loader. The library (glibc) is a critical component in most Linux kernel-based systems, providing functionalities like system calls, program preparation, and execution. The vulnerability has existed since April 2021 with the release of glibc 2.34, and poses a significant risk to major distributions like Fedora, Ubuntu, and Debian.

ShellTorch Exposes Tens of Thousands of Servers Worldwide to Attacks

A critical set of vulnerabilities in the TorchServe AI tool, dubbed "ShellTorch," impacts tens of thousands of internet-exposed servers. TorchServe, maintained by Meta and Amazon, serves PyTorch ML models in production and is used by academic researchers and tech giants such as Amazon, OpenAI, Tesla, Azure, Google, and Intel. The flaws could lead to unauthorized server access and remote code execution. Attacks can be prevented by configuring servers to bind exclusively to local hosts and to fetch models only from trusted domains. Meta and Amazon have acknowledged the issue and encourage developers to use the latest version of TorchServe (0.8.2).

CloudFlare Firewall and DDoS Prevention Vulnerable to Bypass

A new exploit allows attackers to bypass Cloudflare's Firewall and DDoS prevention through flaws in cross-tenant security controls. The attack requires only a free Cloudflare account and the target web server's IP address. The issue stems from Cloudflare's shared infrastructure accepting connections from all tenants and two vulnerabilities in Cloudflare's "Authenticated Origin Pulls" and "Allowlist Cloudflare IP Addresses" features. To mitigate this weakness, use custom certificates and consider Cloudflare Aegis if available.

Tags: DIB, tlp:green