<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>53399</bug_id>
          
          <creation_ts>2004-06-09 05:54 0000</creation_ts>
          <short_desc>net-analyzer/aimsniff symlink attack</short_desc>
          <delta_ts>2004-06-28 08:11:01 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.aimsniff.com/forum/viewtopic.php?t=509</bug_file_loc>
          <status_whiteboard>B3 [glsa? masked]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>gte481z@mail.gatech.edu</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>port001@gentoo.org</cc>
    
    <cc>zhen@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>gte481z@mail.gatech.edu</who>
            <bug_when>2004-06-09 05:54:51 0000</bug_when>
            <thetext>The aimsniff ebuild, version 0.9, contains a security vulnerability.  Currently, it downloads and installs version 0.9b of aimsniff.  This hole, documented by the aimsniff author in a post to the aimsniff forums at:

http://www.aimsniff.com/forum/viewtopic.php?t=509

Can be fixed by updating the ebuild to download and install version 0.9d of aimsniff.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-09 06:01:30 0000</bug_when>
            <thetext>Undisclosed security problem...
ebuild should be updated to use 0.9d.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>zhen@gentoo.org</who>
            <bug_when>2004-06-09 08:49:22 0000</bug_when>
            <thetext>working on it ...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-06-09 08:52:26 0000</bug_when>
            <thetext>I think this software should be remove from portage all together.
Whats next &apos;emerge rootkit&apos;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gte481z@mail.gatech.edu</who>
            <bug_when>2004-06-09 08:59:06 0000</bug_when>
            <thetext>modified the current ebuild and left it on the internet here:

http://www.prism.gatech.edu/~gte481z/aimsniff.html

can not test it now as I am at work.  Will submit an ebuild file and test results when I get back from work tonight.  Anyone who wishes to test the ebuild at that link is welcome.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gte481z@mail.gatech.edu</who>
            <bug_when>2004-06-09 09:02:50 0000</bug_when>
            <thetext>Why remove it from portage?  Aimsniff has legitmate uses such as monitoring employees on company computers to make sure they are not abusing their companies internet use policy or finiancial institutions who are required to log all communication transactions.  It&apos;s just a passive network packet sniffer.  Really just a pretty version of tcpdump or ethereal, and not nearly as dangerous as ettercap (also in portage), speaking of &quot;emerge rootkit&quot;.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-06-09 10:18:07 0000</bug_when>
            <thetext>fair enough.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gte481z@mail.gatech.edu</who>
            <bug_when>2004-06-09 17:19:48 0000</bug_when>
            <thetext>Ebuild sorta seems to work.  I don&apos;t have mysql or apache installed on my box at home to really to test it though.  Someone else will need to take it up from here.  I&apos;m leaving the ebuild modifications I made up on the net at the address above.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>zhen@gentoo.org</who>
            <bug_when>2004-06-10 07:06:02 0000</bug_when>
            <thetext>sorry i haven&apos;t gotten around to this yet. We lost power all last night and this morning due to storms. I will see if I can get to it today.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gte481z@mail.gatech.edu</who>
            <bug_when>2004-06-14 10:29:41 0000</bug_when>
            <thetext>New Ebuild to plug this whole submitted to bugzilla as bug #53905</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2004-06-14 10:56:19 0000</bug_when>
            <thetext>*** Bug 53905 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>zhen@gentoo.org</who>
            <bug_when>2004-06-14 14:29:05 0000</bug_when>
            <thetext>i&apos;m not going to be able to get to this because my releng responsibilities are taking up my time. bug-wranglers?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-17 12:50:00 0000</bug_when>
            <thetext>Vulnerability description available at :
http://www.osvdb.org/displayvuln.php?osvdb_id=6381

We need to find someone to bump or validate the provided ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-06-23 12:06:46 0000</bug_when>
            <thetext>posted a request[1] on gentoo-dev for a dev to take over maintainership of this package.  Nobody responded.  Masking for now.

[1] http://article.gmane.org/gmane.linux.gentoo.devel/19008/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>port001@gentoo.org</who>
            <bug_when>2004-06-23 13:18:10 0000</bug_when>
            <thetext>Even though I&apos;d never use such a package, I hate seeing packages masked due to lack of maintainership. I&apos;ll take care of the bump, looks like the ebuild could use some love. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-24 01:45:50 0000</bug_when>
            <thetext>port001 : you&apos;re welcome :)
Package has been masked in the meantime, updating status whiteboard.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>port001@gentoo.org</who>
            <bug_when>2004-06-27 13:52:33 0000</bug_when>
            <thetext>Bumped ebuild in CVS. Converted the ebuild to use webapp also. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-28 02:00:43 0000</bug_when>
            <thetext>PPC : please test and mark the 0.9-r1 ebuild &quot;~ppc&quot; so that we can unmask it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dholm@gentoo.org</who>
            <bug_when>2004-06-28 02:18:40 0000</bug_when>
            <thetext>It has been marked. Since 0.9 was ~ppc you could have keyworded it yourselves, unless there was a specific reason to remove the keyword.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-06-28 02:55:18 0000</bug_when>
            <thetext>dholm: would&apos;ve done it if I had commit access :)
klieber: I think you can unmask the package.

This is ready for a GLSA vote.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-06-28 08:11:01 0000</bug_when>
            <thetext>unmasking from package.mask. closing without GLSA since this is a ~masked ebuild.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>