<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>195390</bug_id>
          
          <creation_ts>2007-10-10 16:12 0000</creation_ts>
          <short_desc>sys-apps/util-linux &lt; 2.12r-r8 Privilege Escalation Vulnerability (CVE-2007-5191)</short_desc>
          <delta_ts>2008-01-10 09:00:18 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/27145/</bug_file_loc>
          <status_whiteboard>A1 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>keytoaster@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bernd@linx.net</cc>
    
    <cc>chainsaw@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2007-10-10 16:12:06 0000</bug_when>
            <thetext>A vulnerability has been reported in util-linux, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.

The vulnerability is caused due to the mount and umount programs incorrectly checking the return values of the &quot;setuid()&quot; and &quot;setgid()&quot; functions when dropping privileges. This can potentially be exploited to perform certain actions with escalated privileges via e.g. the mount.nfs utility.

The vulnerability is reported in version 2.12r. Other versions may also be affected.

Solution:
Fixed in the util-linux-ng repository.
http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git;a=commit;h=ebbeb2c7ac1b00b6083905957837a271e80b187e</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2007-10-10 16:24:46 0000</bug_when>
            <thetext>You already applied the patch in -r8 a few days ago, but I couldn&apos;t find an appropriate security bug for this issue.

Do you have plans to stabilise util-linux-2.12r-r8? Our latest stable version is vulnerable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2007-10-10 18:04:43 0000</bug_when>
            <thetext>i dont have any plans for anything

whatever security team wants to push is up to them, 2.12r-r8 is fine</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-10-10 20:06:12 0000</bug_when>
            <thetext>Arches pleases test and mark stable sys-apps/util-linux-2.12r-r8
target &quot;alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-10-10 23:06:28 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-10-11 03:12:28 0000</bug_when>
            <thetext>Stable for HPPA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-10-11 03:25:11 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-10-11 03:30:40 0000</bug_when>
            <thetext>Stable for SPARC.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tgall@gentoo.org</who>
            <bug_when>2007-10-11 05:15:26 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-10-11 16:21:36 0000</bug_when>
            <thetext>alpha/ia64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-10-12 15:14:10 0000</bug_when>
            <thetext>ppc stable, ready for glsa</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-12 17:17:28 0000</bug_when>
            <thetext>(In reply to comment #10)
&gt; ppc stable, ready for glsa

request filed.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-10-18 21:53:42 0000</bug_when>
            <thetext>GLSA 200710-18</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2007-11-19 07:20:45 0000</bug_when>
            <thetext>mips stable.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>