<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>143371</bug_id>
          
          <creation_ts>2006-08-09 11:39 0000</creation_ts>
          <short_desc>app-crypt/heimdal setuid issue</short_desc>
          <delta_ts>2006-11-11 20:40:09 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.pdc.kth.se/heimdal/advisory/2006-08-08/</bug_file_loc>
          <status_whiteboard>B1 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kerberos@gentoo.org</cc>
    
    <cc>tcort@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-08-09 11:39:08 0000</bug_when>
            <thetext>2006-08-08: multiple local privilege escalation vulnerabilities
 This problem applies to systems where setuid/seteuid call call fail due to resource exhaustion. One operating system that is true is Linux. The programs that this this problem applies to are ftpd and rcp. The problem only apply to rcp if it installed setuid root (not done by default). 
 Patch (heimdal-0.7.2-setuid-patch) for Heimdal 0.7.2 fixes this problem. 
 One workaround is to make sure set{e,}uid doesn&apos;t fail. Also disabling ftpd and removing the setuid bit from rcp will solve the problem. 
 Thanks to Tom Yu at MIT and Michael Calmer and Marcus Meissner at SUSE for tell us about the problem. Either of CVE-2006-3083 or CVE-2006-3084 describes this problems.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-08-09 11:40:24 0000</bug_when>
            <thetext>Kerberos please provide an updated ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2006-08-10 19:15:16 0000</bug_when>
            <thetext>Ebuild is on its way, sorry for the delay.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2006-08-10 19:20:01 0000</bug_when>
            <thetext>ebuild is in portage.  the patch ball is on its way to the mirrors and is also in my dev.gentoo space (in SRC_URI).  Will remove that some time during the stable marking, after our mirrors have the patchball.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2006-08-10 19:31:18 0000</bug_when>
            <thetext>adding arches, btw</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tsunam@gentoo.org</who>
            <bug_when>2006-08-10 20:56:26 0000</bug_when>
            <thetext>x86 is done, easy enough to test actually.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tcort@gentoo.org</who>
            <bug_when>2006-08-10 21:51:03 0000</bug_when>
            <thetext>amd64 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tcort@gentoo.org</who>
            <bug_when>2006-08-11 08:05:53 0000</bug_when>
            <thetext>alpha stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-08-11 14:01:17 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-08-11 14:36:19 0000</bug_when>
            <thetext>Stable on SPARC</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2006-08-12 07:45:25 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>killerfox@gentoo.org</who>
            <bug_when>2006-08-12 08:15:48 0000</bug_when>
            <thetext>stable on hppa</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-08-12 08:35:04 0000</bug_when>
            <thetext>This is ready for GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-08-23 12:24:20 0000</bug_when>
            <thetext>GLSA 200608-21 , thanks to all and especially daxo&apos;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2006-09-03 13:36:17 0000</bug_when>
            <thetext>0.7.2-r3 stable on mips.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>