Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 439340 - www-servers/monkeyd: Multiple vulnerabilities (CVE-2012-{4442,4443,5303})
Summary: www-servers/monkeyd: Multiple vulnerabilities (CVE-2012-{4442,4443,5303})
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-10-22 22:44 UTC by GLSAMaker/CVETool Bot
Modified: 2012-10-23 19:06 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-10-22 22:44:07 UTC
CVE-2012-5303 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5303):
  Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary
  files via a symlink attack on a PID file, as demonstrated by a pathname
  different from the default /var/run/monkey.pid pathname.

CVE-2012-4443 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4443):
  Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root
  during execution of CGI scripts, which might allow local users to gain
  privileges by leveraging cgi-bin write access.

CVE-2012-4442 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4442):
  Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root
  account during operations with a non-root effective UID, which might allow
  local users to bypass intended file-read restrictions by leveraging a race
  condition in a file-permission check.


Anthony, can you please check these affect any of the versions in the tree?
Comment 1 Anthony Basile gentoo-dev 2012-10-22 23:27:17 UTC
Thanks for the report.  There are no vulnerable versions in the tree.
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-23 19:06:43 UTC
(In reply to comment #1)
> Thanks for the report.  There are no vulnerable versions in the tree.

Thanks for checking!