Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 639064 (CVE-2017-16611) - <x11-libs/libXfont-1.5.4, <x11-libs/libXfont2-2.0.3: Open files with O_NOFOLLOW (symlink attack)
Summary: <x11-libs/libXfont-1.5.4, <x11-libs/libXfont2-2.0.3: Open files with O_NOFOLL...
Status: RESOLVED FIXED
Alias: CVE-2017-16611
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://marc.info/?l=freedesktop-xorg...
Whiteboard: A3 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-11-28 16:04 UTC by Ian Zimmerman
Modified: 2018-01-09 00:46 UTC (History)
1 user (show)

See Also:
Package list:
=x11-libs/libXfont2-2.0.3 =x11-libs/libXfont-1.5.4
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ian Zimmerman 2017-11-28 16:04:26 UTC
according to a posting on oss-security [1]:

X.Org has just release libXfont 1.5.4 and libXfont2 2.0.3 which
contain the following security fix:

Author:     Michal Srb <msrb@suse.com>
AuthorDate: Thu Oct 26 09:48:13 2017 +0200
Commit:     Matthieu Herrb <matthieu@herrb.eu>
CommitDate: Sat Nov 25 11:46:50 2017 +0100

    Open files with O_NOFOLLOW. (CVE-2017-16611)

    A non-privileged X client can instruct X server running under root
    to open any file by creating own directory with "fonts.dir",
    "fonts.alias" or any font file being a symbolic link to any other
    file in the system. X server will then open it. This can be issue
    with special files such as /dev/watchdog.

[1]
http://openwall.com/lists/oss-security/2017/11/28/7


Reproducible: Always
Comment 1 D'juan McDonald (domhnall) 2017-11-28 21:28:50 UTC
Thank you Ian.

@maintainters(s): after bump, please call for stabilization when ready, thank you.


Gentoo Security Padawan
(jmbailey/mbailey_j)
Comment 2 Matt Turner gentoo-dev 2017-11-29 01:42:40 UTC
Now in tree. Please proceed with stabilization.
Comment 3 Agostino Sarubbo gentoo-dev 2017-11-29 11:19:50 UTC
amd64 stable
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-11-29 18:54:35 UTC
x86 stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2017-11-29 20:31:37 UTC
sparc stable (thanks to Rolf Eike Beer)
Comment 6 Tobias Klausmann (RETIRED) gentoo-dev 2017-11-30 20:21:38 UTC
Stable on alpha.
Comment 7 Sergei Trofimovich (RETIRED) gentoo-dev 2017-12-01 07:35:49 UTC
hppa/ia64/ppc/ppc64 stable
Comment 8 Markus Meier gentoo-dev 2017-12-13 21:06:23 UTC
arm stable, all arches done.
Comment 9 D'juan McDonald (domhnall) 2018-01-05 03:16:40 UTC
Thank you A/Ts, @maintainters, please cleanup.
Comment 10 Larry the Git Cow gentoo-dev 2018-01-05 15:30:07 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=679466474ee4f6448fa2a8b706aef63c3d321e8d

commit 679466474ee4f6448fa2a8b706aef63c3d321e8d
Author:     Mart Raudsepp <leio@gentoo.org>
AuthorDate: 2018-01-05 15:25:21 +0000
Commit:     Mart Raudsepp <leio@gentoo.org>
CommitDate: 2018-01-05 15:29:59 +0000

    x11-libs/libXfont2: security cleanup
    
    Bug: https://bugs.gentoo.org/639064
    Package-Manager: Portage-2.3.19, Repoman-2.3.6

 x11-libs/libXfont2/Manifest               |  1 -
 x11-libs/libXfont2/libXfont2-2.0.2.ebuild | 33 -------------------------------
 2 files changed, 34 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4cd874980bf4301152a5c9a0bca844c1d3af5a94

commit 4cd874980bf4301152a5c9a0bca844c1d3af5a94
Author:     Mart Raudsepp <leio@gentoo.org>
AuthorDate: 2018-01-05 15:19:57 +0000
Commit:     Mart Raudsepp <leio@gentoo.org>
CommitDate: 2018-01-05 15:29:50 +0000

    x11-libs/libXfont: security cleanup
    
    Bug: https://bugs.gentoo.org/639064
    Package-Manager: Portage-2.3.19, Repoman-2.3.6

 x11-libs/libXfont/Manifest              |  1 -
 x11-libs/libXfont/libXfont-1.5.3.ebuild | 34 ---------------------------------
 2 files changed, 35 deletions(-)}
Comment 11 D'juan McDonald (domhnall) 2018-01-05 18:36:37 UTC
New GLSA request filed.


Gentoo Security Padawan
(Jmbailey/mbailey_j)
Comment 12 Thomas Deutschmann (RETIRED) gentoo-dev 2018-01-09 00:46:48 UTC
This issue was resolved and addressed in
 GLSA 201801-10 at https://security.gentoo.org/glsa/201801-10
by GLSA coordinator Thomas Deutschmann (whissi).