<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>61797</bug_id>
          
          <creation_ts>2004-08-26 05:50 0000</creation_ts>
          <short_desc>app-arch/star suid root vulnerability</short_desc>
          <delta_ts>2006-05-30 02:42:12 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>https://lists.berlios.de/pipermail/star-users/2004-August/000239.html</bug_file_loc>
          <status_whiteboard>C1 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>wschlich@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>lostlogic@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>wschlich@gentoo.org</who>
            <bug_when>2004-08-26 05:50:49 0000</bug_when>
            <thetext>--8&lt;--
A problem exists for all star versions that
did support to use ssh for remote tape access.

The problem is present in star-1.5a09 ... star-1.5a45

Please upgrade to star-1.5a46
--8&lt;--
The latest version available in portage is app-arch/star-1.5_alpha43.
It should be noted that star currently is not SUID by default.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-26 06:46:42 0000</bug_when>
            <thetext>lostlogic you bumped last time please bump to latest version.

Currently no more info on the issue.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-28 15:31:13 0000</bug_when>
            <thetext>Bump compiles fine.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-08-31 01:31:03 0000</bug_when>
            <thetext>ebuild bumped to star-1.5_alpha46 (Runtime needs testing)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-08-31 01:43:42 0000</bug_when>
            <thetext>Arches please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2004-08-31 05:43:10 0000</bug_when>
            <thetext>Sparc tasty.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-08-31 16:24:56 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>sejo@gentoo.org</who>
            <bug_when>2004-09-01 13:48:55 0000</bug_when>
            <thetext>tested and stable on ppc


greetings</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-02 01:00:17 0000</bug_when>
            <thetext>Reassigning Product/Component as this is not a GLSA error, it&apos;s a security bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lv@gentoo.org</who>
            <bug_when>2004-09-02 01:54:58 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-09-05 03:20:06 0000</bug_when>
            <thetext>Local priv escalation.

x86 please mark stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2004-09-06 11:03:01 0000</bug_when>
            <thetext>Stable on IA64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2004-09-07 13:57:09 0000</bug_when>
            <thetext>stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-07 14:00:53 0000</bug_when>
            <thetext>GLSA-ready</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-09-07 21:36:06 0000</bug_when>
            <thetext>hppa stable now</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-08 00:54:35 0000</bug_when>
            <thetext>GLSA 200409-11</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2006-05-29 17:23:56 0000</bug_when>
            <thetext>The GLSA sent our for this bug has an error

      &lt;unaffected range=&quot;ge&quot;&gt;star-1.5_alpha46&lt;/unaffected&gt;
      &lt;vulnerable range=&quot;lt&quot;&gt;star-1.5_alpha46&lt;/vulnerable&gt;

Should read:

      &lt;unaffected range=&quot;ge&quot;&gt;1.5_alpha46&lt;/unaffected&gt;
      &lt;vulnerable range=&quot;lt&quot;&gt;1.5_alpha46&lt;/vulnerable&gt;

Ref:
http://www.gentoo.org/security/en/glsa/glsa-200409-11.xml?passthru=1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-05-30 02:42:12 0000</bug_when>
            <thetext>Thanks Kugelfang/solar. Should be fixed in the tree.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>