Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 391879 (CVE-2011-4349) - <x11-misc/colord-0.1.14-r1 Multiple SQL Injection Vulnerabilities (CVE-2011-4349)
Summary: <x11-misc/colord-0.1.14-r1 Multiple SQL Injection Vulnerabilities (CVE-2011-4...
Status: RESOLVED FIXED
Alias: CVE-2011-4349
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/46940/
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-11-25 17:06 UTC by Agostino Sarubbo
Modified: 2011-12-13 00:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-11-25 17:06:36 UTC
From secunia security advisory at $URL:

Description:
Certain unspecified input is not properly sanitised in cd-mapping-db.c and cd-device-db.c before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.


Solution:
Fixed in the GIT repository.
https://bugs.freedesktop.org/show_bug.cgi?id=42904
Comment 1 Alexandre Rostovtsev (RETIRED) gentoo-dev 2011-11-25 18:18:23 UTC
Good thing we are not running colord as root, unlike some other distros :)

I have added the upstream patches to colord-0.1.14-r1

I am not sure if a GLSA is necessary since all versions of colord are in ~arch.

>*colord-0.1.14-r1 (25 Nov 2011)
> 
>  25 Nov 2011; Alexandre Rostovtsev <tetromino@gentoo.org>
>  -colord-0.1.12.ebuild, -colord-0.1.13.ebuild, +colord-0.1.14-r1.ebuild,
>  +files/colord-0.1.14-sql-injections.patch,
>  +files/colord-0.1.14-sql-injections-2.patch:
>  Add patches to fix SQL injections (bug #391879, thanks to Agostino Sarubbo for
>  reporting). Allow building against freebsd's libusb (bug #387959, thanks to
>  Naohiro Aota). Drop old versions.
Comment 2 Agostino Sarubbo gentoo-dev 2011-11-25 18:22:32 UTC
(In reply to comment #1)
> I am not sure if a GLSA is necessary since all versions of colord are in ~arch.
noglsa, thanks for bump it.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2011-12-13 00:07:21 UTC
CVE-2011-4349 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4349):
  Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2)
  cd-device-db.c in colord before 0.1.15 allow local users to execute
  arbitrary SQL commands via vectors related to color devices and (a) device
  id, (b) property, or (c) profile id.