First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 69868
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Ulrich Müller <ulm@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 69868 depends on: Show dependency tree
Show dependency graph
Bug 69868 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-11-02 12:09 0000
app-sci/gimps-23.9 installs /opt/gimps/mprime with ownership nobody:nogroup.
In the default configuration, the initscript executes it as root user.
If /opt is mounted via NFS, it might be possible to overwrite mprime by an arbitrary binary.

The same applies to the stable -23.5 version.

(Probably, it should be the other way around: the binary should be owned by root and run as a special user.)

------- Comment #1 From Sune Kloppenborg Jeppesen 2004-11-02 13:00:28 0000 -------
Hi Michal,

Please commit a fixed version.

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-11-04 13:31:20 0000 -------
sci please fix setiathome,chessbrain and any other applications with similar
issues.

------- Comment #3 From Michal Januszewski 2004-11-04 14:39:59 0000 -------
Gimps is now fixed.

------- Comment #4 From Sune Kloppenborg Jeppesen 2004-11-06 07:18:58 0000 -------
sci please fix this ASAP.

------- Comment #5 From Olivier Fisette 2004-11-07 11:18:03 0000 -------
Fixed for "app-sci/chessbrain".

"app-sci/foldingathome" is also affected.

------- Comment #6 From Sune Kloppenborg Jeppesen 2004-11-07 12:13:17 0000 -------
Thanks Olivier. 

sci please fix foldingathome also.

------- Comment #7 From Olivier Fisette 2004-11-07 12:20:09 0000 -------
Fixed "app-sci/setiathome-3.08" (the version for x86 and amd64).

Could someone with access to either ppc, sparc, hppa or ia64 please do the same for version 3.03? This seems to be the last affected package.

"app-sci/foldingathome" is not affected. (That was my mistake.)

------- Comment #8 From Sune Kloppenborg Jeppesen 2004-11-07 12:56:55 0000 -------
Olivier just update the ebuilds and mark stable on the arches you have access
to. Security will handle stable marking for other arches.

------- Comment #9 From Olivier Fisette 2004-11-07 13:32:01 0000 -------
Fixed "app-sci/setiathome-3.03". All four supported arches are marked unstable.

------- Comment #10 From Sune Kloppenborg Jeppesen 2004-11-07 13:46:38 0000 -------
Arches please mark setiathome stable. Fixed versions are 3.03-r2 and 3.08-r4.

Combined target keywords for setiathome:

x86 amd64 ppc sparc -alpha hppa ia64

------- Comment #11 From Ferris McCormick 2004-11-08 05:56:38 0000 -------
sparc has following problems with setiathome-3.03-r2:
1) If you happen to have USE='X', installation fails because there is no xsetiathome;
2) If you do not have USE='X', the program installed at /opt/setiathome/setiathome is
   not made executable:  You need to do 'chmod +x /opt/setiathome/setihome' by hand.
(Previous 3.03-r1 ebuild takes care of this, but I do not know if the deletion was intentional or not.
In any event, as it stands, what is installed for -r2 cannot be used but -r1 can be.)
========================
setiathome-3.08 is a nonstarter for sparc, since it does not actually exist.

Regards,
Ferris

------- Comment #12 From Sune Kloppenborg Jeppesen 2004-11-08 06:53:12 0000 -------
Back to ebuild status.  Olivier please fix.

------- Comment #13 From Olivier Fisette 2004-11-08 07:41:33 0000 -------
Should be fixed in CVS, but I cannot test it.

------- Comment #14 From Ferris McCormick 2004-11-08 08:21:45 0000 -------
setiathome-3.03-r2 now installs and runs for sparc; sparc done.

------- Comment #15 From Sune Kloppenborg Jeppesen 2004-11-08 11:19:29 0000 -------
Back to stable marking. Thx Olivier.

------- Comment #16 From Jochen Maes (RETIRED) 2004-11-09 01:23:28 0000 -------
setiathome stable on ppc

------- Comment #17 From Sune Kloppenborg Jeppesen 2004-11-13 00:00:27 0000 -------
Thx Ferris. Please remember to remove arch from CC when you mark stable.

------- Comment #18 From Ferris McCormick 2004-11-13 05:06:27 0000 -------
Sorry.  It wasn't completely clear to me that setiathome was the only thing
that needed looking at.  (Although I guess Comment 7 gives a pretty good
indication.)

------- Comment #19 From Sune Kloppenborg Jeppesen 2004-11-14 10:36:06 0000 -------
GLSA drafted Security please review.

------- Comment #20 From Sune Kloppenborg Jeppesen 2004-11-17 14:28:00 0000 -------
GLSA 200411-26

sci please remember to remove old vulnerable ebuilds that are no longer needed.

------- Comment #21 From Olivier Fisette 2004-11-18 05:53:48 0000 -------
Removed insecure versions for "app-sci/{gimp,chessbrain}". Must hppa and ia64 
mark "app-sci/setiathome-3.03-r2" stable before I remove r1, or should I remove 
it immediately?

------- Comment #22 From Thierry Carrez (RETIRED) 2004-11-18 14:01:30 0000 -------
Yes, you should remove r1 only when hppa and ia64 mark
"app-sci/setiathome-3.03-r2" stable.

------- Comment #23 From René Nussbaumer 2005-06-26 05:03:48 0000 -------
Removed hppa keyword because the tarball is not available

First Last Prev Next    No search results available      Search page      Enter new bug