First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 136807
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 136201
Assigned To: Gentoo KDE team <kde@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jure Repinc <jlp.bugs@gmail.com>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 136807 depends on: Show dependency tree
Bug 136807 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-06-14 11:37 0000
~/.dmrc symlink attack vulnerability (CVE-2006-2449) has been discovered in
KDM. The fix is already available here:
http://lists.kde.org/?l=kde-commits&m=115030948832301&w=2
It would be gret to have the fix in Gentoo as soon as possible.

------- Comment #1 From Jure Repinc 2006-06-14 11:48:57 0000 -------
More info

KDE Security Advisory: KDM symlink attack vulnerability
Original Release Date: 2006-06-14
URL: http://www.kde.org/info/security/advisory-20060614-1.txt

0. References

        CVE-2006-2449


1. Systems affected:

        KDM as shipped with KDE 3.2.0 up to including 3.5.3. KDE 3.1.x and
        older and newer versions than KDE 3.5.3 are not affected. 


2. Overview:

        KDM allows the user to select the session type for login. This
        setting is permanently stored in the user home directory. By
        using a symlink attack, KDM can be tricked into allowing the
        user to read file content that would otherwise be unreadable
        to this particular user. This vulnerability was discovered
        and reported by Ludwig Nussel.


3. Impact:

        KDM might allow a normal user to read the content of /etc/shadow
        or other files, which allows compromising the privacy of another
        user or even the security of the whole system.

4. Solution:

        Source code patches have been made available which fix these
        vulnerabilities. Contact your OS vendor / binary package provider
        for information about how to obtain updated binary packages.


5. Patch:

        A patch for KDE 3.4.0 - KDE 3.5.3 is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        9daecff07d57dabba35da247e752916a  post-3.5.0-kdebase-kdm.diff

        A patch for KDE 3.3.x is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        f2e1424d97f2cd18674bef833274c5e3  post-3.3.0-kdebase-kdm.diff

        A patch for KDE 3.2.x is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        8aa6b41cccca4216c6eb1cf705c2370a  post-3.2.0-kdebase-kdm.diff

------- Comment #2 From Diego E. 'Flameeyes' Pettenò 2006-06-14 12:19:06 0000 -------

*** This bug has been marked as a duplicate of 136201 ***

First Last Prev Next    No search results available      Search page      Enter new bug