<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>198209</bug_id>
          <alias>CVE-2007-5827</alias>
          <creation_ts>2007-11-05 20:51 0000</creation_ts>
          <short_desc>sys-block/iscsitarget &lt; 0.4.15-r1 insecure file permission (CVE-2007-5827)</short_desc>
          <delta_ts>2007-11-06 04:30:59 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/27483/</bug_file_loc>
          <status_whiteboard>~3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>trivial</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>py@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>robbat2@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-05 20:51:50 0000</bug_when>
            <thetext>Description:
A weakness has been discovered in iSCSI Enterprise Target, which can be exploited by malicious, local users to disclose sensitive information.

The weakness is caused due to the install script applying world readable permissions to the &quot;/etc/ietd.conf&quot; file, which can be exploited to e.g. disclose user names and passwords.

The weakness is confirmed in version 0.4.15. Other versions may also be affected.

Solution:
Apply correct file permissions to &quot;/etc/ietd.conf&quot;.

Provided and/or discovered by:
Reported in a Debian bug by Martin Zobel-Helas.

Original Advisory:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=448873</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-05 20:54:38 0000</bug_when>
            <thetext>robbat2, please provide a fixed ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>robbat2@gentoo.org</who>
            <bug_when>2007-11-06 00:42:41 0000</bug_when>
            <thetext>in cvs.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-06 01:14:19 0000</bug_when>
            <thetext>Thanks for the fast fix.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>