<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>103719</bug_id>
          
          <creation_ts>2005-08-25 09:48 0000</creation_ts>
          <short_desc>net-misc/ntp small security issue (CAN-2005-2496)</short_desc>
          <delta_ts>2005-08-26 00:34:46 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>https://ntp.isc.org/bugs/show_bug.cgi?id=392</bug_file_loc>
          <status_whiteboard>A4 [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-25 09:48:23 0000</bug_when>
            <thetext>When starting xntpd with the -u option and specifying the group 
by using a string not a numeric gid the daemon uses the gid of 
the user not the group. 
 
reproduce: 
        # rcxntpd start  
        # ps -C ntpd -o comm,pid,ruser,euser,rgroup,egroup 
        verify given and real IDs</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-25 09:49:19 0000</bug_when>
            <thetext>Created an attachment (id=66876)
ntpd-using_wrong_group.diff

SUSE patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-25 09:51:18 0000</bug_when>
            <thetext>Mike please verify and patch as needed. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-08-25 10:16:04 0000</bug_when>
            <thetext>no point in restricting this, it&apos;s been public knowledge for like 6 months now ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-25 11:01:37 0000</bug_when>
            <thetext>heh, anyways I just want an updated ebuild:-) </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-08-25 11:20:47 0000</bug_when>
            <thetext>it&apos;s been fixed in upstream dev branch ... i want to see about stable branch
too, but i&apos;ll prob do ebuilds in the meantime</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-08-25 15:10:36 0000</bug_when>
            <thetext>added fixed ebuilds to portage

do a glsa if you want ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-25 21:21:21 0000</bug_when>
            <thetext>Thx SpanKY. 
 
Time for GLSA decision, I vote NO. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-08-26 00:34:46 0000</bug_when>
            <thetext>Voting NO too, I can&apos;t see this being provoked and/or exploited in any way.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>66876</attachid>
            <date>2005-08-25 09:49 0000</date>
            <desc>ntpd-using_wrong_group.diff</desc>
            <filename>ntpd-using_wrong_group.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIG50cGQvbnRwZC5jLm9yaWcJMjAwNS0wMi0xMCAxMjoyMDoyOC4wMDAwMDAwMDAgKzAxMDAK
KysrIG50cGQvbnRwZC5jCTIwMDUtMDItMTAgMTI6MjE6MDMuMDAwMDAwMDAwICswMTAwCkBAIC04
ODEsNyArODgxLDcgQEAKIAkJCX0gZWxzZSB7CiBnZXRncm91cDoJCiAJCQkJaWYgKChnciA9IGdl
dGdybmFtKGdyb3VwKSkgIT0gTlVMTCkgewotCQkJCQlzd19naWQgPSBwdy0+cHdfZ2lkOworCQkJ
CQlzd19naWQgPSBnci0+Z3JfZ2lkOwogCQkJCX0gZWxzZSB7CiAJCQkJCWVycm5vID0gMDsKIAkJ
CQkJbXN5c2xvZyhMT0dfRVJSLCAiQ2Fubm90IGZpbmQgZ3JvdXAgYCVzJyIsIGdyb3VwKTsK
</data>        

          </attachment>
    </bug>

</bugzilla>