Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 152104 - sys-cluster/torque <= 2.0.0p8 insecure spool file (CVE-2006-5677)
Summary: sys-cluster/torque <= 2.0.0p8 insecure spool file (CVE-2006-5677)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://csirt.fe.up.pt/docs/TORQUE-aud...
Whiteboard: C1 [glsaupdate] aetius
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-20 06:22 UTC by Matt Drew (RETIRED)
Modified: 2007-01-09 14:34 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Drew (RETIRED) gentoo-dev 2006-10-20 06:22:48 UTC
Not sure what version this is against, but we have several in portage with the 1.2 series being stable.  The audit was done apparently in March, so it could be 1.0 or 1.2 which was added to portage in February.  The torque changelog doesn't mention this particular problem:

http://clusterresources.com/torquedocs20/changelog.shtml
Comment 1 Matt Drew (RETIRED) gentoo-dev 2006-10-20 06:34:15 UTC
version is <= 2.0.0p8 (missed it on the actual email)
Comment 2 Matt Drew (RETIRED) gentoo-dev 2006-11-10 07:57:16 UTC
cc'ing herd.
Comment 3 Donnie Berkholz (RETIRED) gentoo-dev 2006-11-10 08:36:55 UTC
OK, let's stable torque-2.1.2-r2. That will also require a couple other stabilizations.

To stable:

x86: torque-2.1.2-r2, openpbs-common-1.1.1
ppc64: torque-2.1.2-r2, openpbs-common-1.1.1, lam-mpi-7.1.2

No other architectures have a stable torque.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-10 09:39:53 UTC
Arches please test and mark stable. Target keywords are:

~amd64 ~ppc ppc64 x86
Comment 5 Markus Meier gentoo-dev 2006-11-10 12:57:50 UTC
sys-cluster/torque-2.1.2-r2  USE="crypt -server -tk"
sys-cluster/openpbs-common-1.1.1

1. both packages emerge fine on x86
2. pass collision test
have no idea how to test this...

Portage 2.1.1-r1 (default-linux/x86/2006.1/desktop, gcc-4.1.1, glibc-2.4-r4, 2.6.18.1 i686)
=================================================================
System uname: 2.6.18.1 i686 Genuine Intel(R) CPU           T2300  @ 1.66GHz
Gentoo Base System version 1.12.6
Last Sync: Fri, 10 Nov 2006 19:30:01 +0000
ccache version 2.3 [disabled]
app-admin/eselect-compiler: [Not Present]
dev-java/java-config: 1.3.7, 2.0.30
dev-lang/python:     2.3.5-r3, 2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.3
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.60
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.13-r4
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r1
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=prescott -pipe -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config /usr/share/texmf/dvipdfm/config/ /usr/share/texmf/dvips/config/ /usr/share/texmf/tex/generic/config/ /usr/share/texmf/tex/platex/config/ /usr/share/texmf/xdvi/"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/terminfo /etc/texmf/web2c"
CXXFLAGS="-O2 -march=prescott -pipe -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
EMERGE_DEFAULT_OPTS="--nospinner"
FEATURES="autoconfig collision-protect distlocks metadata-transfer parallel-fetch sandbox sfperms strict test userfetch userpriv usersandbox"
GENTOO_MIRRORS="http://mirror.switch.ch/mirror/gentoo/ http://gentoo.inode.at/"
LINGUAS="en de en_GB de_CH"
MAKEOPTS="-j3"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude='/distfiles' --exclude='/local' --exclude='/packages'"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="x86 X a52 aac acpi alsa apache2 asf berkdb bitmap-fonts cairo cdr cdrom cli cracklib crypt cups dbus divx dlloader dri dts dvd dvdr dvdread eds elibc_glibc emboss encode fam ffmpeg firefox flac fortran gdbm gif gnome gpm gstreamer gtk hal iconv input_devices_keyboard input_devices_mouse ipv6 isdnlog java jpeg kde kdeenablefinal kernel_linux ldap libg++ linguas_de linguas_de_CH linguas_en linguas_en_GB mad mikmod mmx mono mp3 mpeg ncurses nls nptl nptlonly ogg opengl oss pam pcre perl png ppds pppd python qt3 qt4 quicktime readline reflection rtsp samba sdl session smp spell spl sse sse2 sse3 ssl svg tcpd test tetex theora threads truetype truetype-fonts type1-fonts udev unicode userland_GNU vcd video_cards_fbdev video_cards_i810 video_cards_vesa vorbis win32codecs wxwindows x264 xine xml xorg xprint xv xvid zlib"
Unset:  CTARGET, INSTALL_MASK, LANG, LC_ALL, LDFLAGS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 6 Andrej Kacian (RETIRED) gentoo-dev 2006-11-10 16:34:49 UTC
(In reply to comment #3)
> x86: torque-2.1.2-r2, openpbs-common-1.1.1

Stabilized.
Comment 7 Markus Rothe (RETIRED) gentoo-dev 2006-11-15 04:51:14 UTC
ppc64 stable

last arch -> marking FIXED
Comment 8 Matthias Geerdsen (RETIRED) gentoo-dev 2006-11-15 12:44:08 UTC
corsair, please don't close security bugs, we usually close them after GLSA publication (if necessary)

this has been rated C1 -> GLSA
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-21 06:28:06 UTC
GLSA 200611-14
Comment 10 Donnie Berkholz (RETIRED) gentoo-dev 2006-11-22 23:17:12 UTC
I regret to inform you of a mistake in part because of the horrendous tardiness of upstream to fix these holes. This security issue in fact was not fixed until 2.1.6, which I've just added to the tree to stabilize.

2.1.6:
  b - additional spool handling security fixes
2.1.4 (a ghost release that doesn't actually exist on the site):
  b - Fix "Spool Job Race condition"

So x86/ppc64 will need to again stabilize this.
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-23 03:59:30 UTC
Bah, not a new GLSA for this stupid issue:(

Arches please test and mark stable. Target keywords are:

torque-2.1.6.ebuild:KEYWORDS="~amd64 ~ppc ppc64 x86"
Comment 12 Brent Baude (RETIRED) gentoo-dev 2006-11-23 06:01:53 UTC
ppc64 stable
Comment 13 Christian Faulhammer (RETIRED) gentoo-dev 2006-11-23 23:26:30 UTC
Stable on x86
Comment 14 Christian Faulhammer (RETIRED) gentoo-dev 2006-11-23 23:26:53 UTC
Sorry, forgot the GLSA
Comment 15 Donnie Berkholz (RETIRED) gentoo-dev 2006-11-24 01:08:40 UTC
This could probably use some investigation into openpbs too, since torque is basically a heavily enhanced version of openpbs. Would anyone like to look into it?
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-24 02:01:26 UTC
GLSA updated.
Comment 17 Donnie Berkholz (RETIRED) gentoo-dev 2006-11-24 02:22:24 UTC
(In reply to comment #16)
> GLSA updated.

I hope "temporary" is spelled correctly in the subject this time. =)
Comment 18 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-24 02:28:41 UTC
Duh! GLSA updated again:-)
Comment 19 Matt Drew (RETIRED) gentoo-dev 2006-12-06 06:14:20 UTC
(In reply to comment #15)
> This could probably use some investigation into openpbs too, since torque is
> basically a heavily enhanced version of openpbs. Would anyone like to look into
> it?
> 

Donnie - see bug #153495, I think.
Comment 20 Matt Drew (RETIRED) gentoo-dev 2007-01-09 14:34:48 UTC
closing this - we're done here.