First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 63187
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Alin Năstac <mrness@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
scsi-remote.c.diff scsi-remote.c.diff patch Alin Năstac 2004-09-07 22:08 0000 540 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 63187 depends on: Show dependency tree
Show dependency graph
Bug 63187 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-09-07 22:05 0000
I've looked into cdrecord-2.01-0.a28.2.100mdk package from Mandrake and saw a
patch that isn't included in our current stable cdrecord ebuild. Also, I
suspect that patch could also be applied to cdrecord-prodvd but I didn't
verified.

------- Comment #1 From Alin Năstac 2004-09-07 22:08:30 0000 -------
Created an attachment (id=39179) [edit]
scsi-remote.c.diff

Resolve MDKSA-2004:091 issue.

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-09-07 22:42:30 0000 -------
Pylon please verify and apply.

Mandrake advisory:

Max Vozeler found that the cdrecord program, which is suid root, fails to drop euid=0 when it exec()s a program specified by the user through the $RSH environment variable. This can be abused by a local attacker to obtain root privileges.


This has been assigned CAN-2004-0806

------- Comment #3 From Lars Weiler (RETIRED) 2004-09-08 07:13:32 0000 -------
We don't install cdrecord suid root by default.  The user has to act to change
it's state.  E.g. k3b's setup utility allows to change the state, but we warn
about it during installation of k3b.

I don't think that we need to apply the patch.  Security-team, you have the
last word.

------- Comment #4 From Alin Năstac 2004-09-08 07:27:13 0000 -------
My 2 eurocents:
I think it would be best to apply this patch, even if security don't issue a glsa. Prolly there are gentooers who choosed to suid their cdrecord. Why not secure their cdrecord?

------- Comment #5 From Thierry Carrez (RETIRED) 2004-09-08 07:50:08 0000 -------
I would say the patch should be applied. It's not the first time that we issue
a GLSA on a non-by-default setup. And cdrecord must be SUID on a lot of
machines.

------- Comment #6 From solar 2004-09-08 16:52:12 0000 -------
I would add the patch and skip the GLSA process.

------- Comment #7 From SpanKY 2004-09-08 20:05:27 0000 -------
agreed, theres no reason not to add the patch

although people would have to +s cdrecord themselves i'd imagine people do since k3b supports it as such

------- Comment #8 From Sune Kloppenborg Jeppesen 2004-09-09 12:05:08 0000 -------
Pylon please apply the patch.

------- Comment #9 From solar 2004-09-13 22:47:06 0000 -------
The maintainer took to long so I added the patch to the following ebuilds.
cdrtools-2.01_alpha28-r2.ebuild
cdrtools-2.01_alpha37-r1.ebuild

We should still probably have the arches mark these stable. 
Perferably 2.01_alpha37-r1 and then remove the old ebuilds.

cdrtools-2.01_alpha28-r2
KEYWORDS="~x86 ~ppc ~sparc ~alpha ~hppa ~amd64 ~ia64 ~ppc64 ~mips"

cdrtools-2.01_alpha37-r1
KEYWORDS="~x86 ~ppc ~sparc ~alpha ~hppa ~amd64 ~ia64 ~ppc64 ~mips"

------- Comment #10 From Sune Kloppenborg Jeppesen 2004-09-13 23:57:21 0000 -------
Arches please test and mark stable. Preferably 2.01_alpha37-r1 otherwise
2.01_alpha28-r2.

------- Comment #11 From Alin Năstac 2004-09-14 00:01:37 0000 -------
jaervosz, don't forget about cdrecord-prodvd

------- Comment #12 From Alin Năstac 2004-09-14 00:28:11 0000 -------
cdrrecord-prodvd does not compile cdrtools by itself.
thanks jaervosz for observing that.
sorry folks, my mistake.

------- Comment #13 From Lars Weiler (RETIRED) 2004-09-14 02:41:32 0000 -------
Sorry, I was not around the last days.

One sidenote: cdrtools-2.01_alpha37 could have some problems with kernel <2.6.8 and audio-cd-writing.  Furthermore I'm about to add cdrtools-2.01 (the stable version) to the tree.

------- Comment #14 From Sune Kloppenborg Jeppesen 2004-09-14 05:43:40 0000 -------
Thx Pylon. Arches please test and mark stable. Preferably 2.01 (just added)
otherwise 2.01_alpha37-r1 or 2.01_alpha28-r2.

------- Comment #15 From Gustavo Zacarias (RETIRED) 2004-09-14 08:05:25 0000 -------
2.01 stable on sparc, tested audio on 2.4 with -v -dao -pad just fine, also
iso.

------- Comment #16 From Guy Martin 2004-09-14 09:16:37 0000 -------
Stable on hppa.

------- Comment #17 From Jason Huebel 2004-09-14 10:08:15 0000 -------
2.01 stable on amd64

------- Comment #18 From Lars Weiler (RETIRED) 2004-09-14 10:58:23 0000 -------
2.01 stable on x86 and ppc.

------- Comment #19 From Thierry Carrez (RETIRED) 2004-09-14 11:19:52 0000 -------
GLSA drafted, security please review

------- Comment #20 From Sune Kloppenborg Jeppesen 2004-09-14 14:29:21 0000 -------
GLSA 200409-18

alpha,ia64,mips,ppc64 don't forget to mark stable to benifit from GLSA.

------- Comment #21 From Joshua Kinard 2004-09-20 12:30:52 0000 -------
mips stable.

------- Comment #22 From Tom Gall 2004-10-09 12:30:00 0000 -------
thanks, stable on ppc64

First Last Prev Next    No search results available      Search page      Enter new bug