Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 189690
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
star-traversal.diff star-traversal.diff patch Robert Buchholz 2007-08-21 10:38 0000 340 bytes Details | Diff
v.tar v.tar application/octet-stream Robert Buchholz 2007-08-21 10:40 0000 10.00 KB Details
star-1.5_alpha74-multiple-slashes.diff star-1.5_alpha74-multiple-slashes.diff patch Robert Buchholz 2007-08-21 13:57 0000 278 bytes Details | Diff
sparc64-emerge-info sparc64-emerge-info text/plain Jorge Manuel B. S. Vicetto 2007-09-13 12:21 0000 2.51 KB Details
app-arch:star-1.5_alpha84:20070913-105036.log app-arch:star-1.5_alpha84:20070913-105036.log text/plain Jorge Manuel B. S. Vicetto 2007-09-13 12:22 0000 99.25 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 189690 depends on: 185856 Show dependency tree
Bug 189690 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-21 10:37 0000
There is a  directory traversal vulnerability in star that can be exploited by
files in an archive that contain "foo//..//.." as a filename. This is related
to the vulnerability described in bug #189682.

------- Comment #1 From Robert Buchholz 2007-08-21 10:38:44 0000 -------
Created an attachment (id=128754) [details]
star-traversal.diff

Patch to fixing this.

------- Comment #2 From Robert Buchholz 2007-08-21 10:40:03 0000 -------
Created an attachment (id=128756) [details]
v.tar

tar file to exploit this issue (creates a README file outside of the working
dir)

------- Comment #3 From Robert Buchholz 2007-08-21 13:57:52 0000 -------
Created an attachment (id=128776) [details]
star-1.5_alpha74-multiple-slashes.diff

Contacted upstream, this was the proposed patch.

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-08-21 20:38:48 0000 -------
shell-tools please advise and patch as necessary.

------- Comment #5 From Robert Buchholz 2007-08-29 07:02:49 0000 -------
New upstream release AN-1.5a84 fixes this issue.

------- Comment #6 From Wolfram Schlich 2007-09-06 08:22:58 0000 -------
still 1.5a84 is not in portage...

------- Comment #7 From Peter Volkov 2007-09-06 11:55:33 0000 -------
It crashes here. But I've contacted upstream and Joerg gave sent me some
additional fixes. As soon as I test them, I'll bump.

------- Comment #8 From Wolfram Schlich 2007-09-06 12:08:34 0000 -------
(In reply to comment #7)
> It crashes here. But I've contacted upstream and Joerg gave sent me some
> additional fixes. As soon as I test them, I'll bump.
> 

great, thanks :o)

------- Comment #9 From Christian Faulhammer 2007-09-08 21:45:37 0000 -------
Proposing B4 based on severity in bug 189682, setting whiteboard to waiting for
ebuild

------- Comment #10 From Peter Volkov 2007-09-12 18:47:32 0000 -------
Finally ebuild is in the tree.

------- Comment #11 From Tobias Heinlein 2007-09-12 19:05:05 0000 -------
Thanks Peter. Arches, please test and mark stable app-arch/star-1.5_alpha84.
Target keywords are: "alpha amd64 hppa ia64 mips ppc ppc64 sparc x86"

------- Comment #12 From Markus Meier 2007-09-12 20:36:39 0000 -------
x86 stable

------- Comment #13 From Jeroen Roovers 2007-09-13 03:42:55 0000 -------
Stable for HPPA.

------- Comment #14 From Markus Rothe 2007-09-13 11:41:58 0000 -------
ppc64 stable

------- Comment #15 From Raúl Porcel 2007-09-13 11:46:04 0000 -------
alpha/ia64 stable

------- Comment #16 From Jorge Manuel B. S. Vicetto 2007-09-13 12:20:50 0000 -------
The emerge completes here on sparc64 with the following warnings:

RULES/rules1.top:239: incs/Dcc.sparc-linux: No such file or directory
RULES/rules.cnf:56: incs/sparc-linux-cc/Inull: No such file or directory
RULES/rules.cnf:57: incs/sparc-linux-cc/rules.cnf: No such file or directory

../RULES/rules.ins:27: warning: overriding commands for target `/usr/'
../RULES/rules.ins:22: warning: ignoring old commands for target `/usr/'
../RULES/rules.ins:30: warning: overriding commands for target
`../bins/sparc-linux-cc'
../RULES/rules.ins:24: warning: ignoring old commands for target
`../bins/sparc-linux-cc'

The package doesn't run any tests. I was able to create a simple .tar.bz2 file
and to extract it.

------- Comment #17 From Jorge Manuel B. S. Vicetto 2007-09-13 12:21:58 0000 -------
Created an attachment (id=130804) [details]
sparc64-emerge-info

emerge --info for sparc64

------- Comment #18 From Jorge Manuel B. S. Vicetto 2007-09-13 12:22:45 0000 -------
Created an attachment (id=130806) [details]
app-arch:star-1.5_alpha84:20070913-105036.log

Complete emerge log for star-1.5_alpha84

------- Comment #19 From Peter Volkov 2007-09-13 13:19:36 0000 -------
Jorge, I suppose that similar warnings are on all archs and this is a
feature/problem of SSPM ("Slottable Source Plugin Module" system). This should
not stop/delay stabilization.

------- Comment #20 From Jose Luis Rivero (yoswink) 2007-09-13 14:46:45 0000 -------
(In reply to comment #19)
> Jorge, I suppose that similar warnings are on all archs and this is a
> feature/problem of SSPM ("Slottable Source Plugin Module" system). This should
> not stop/delay stabilization.
> 

Then all is ready, sparc stable.
Thanks Jorge for the testing and Peter for the note.

------- Comment #21 From Tobias Scherbaum 2007-09-15 08:20:59 0000 -------
ppc stable

------- Comment #22 From Christoph Mende 2007-09-16 13:52:02 0000 -------
amd64 stable

------- Comment #23 From Robert Buchholz 2007-09-16 14:18:11 0000 -------
All but mips stable, next is glsa decision.

------- Comment #24 From Sune Kloppenborg Jeppesen 2007-09-24 16:27:41 0000 -------
I tend to vote NO.

------- Comment #25 From Pierre-Yves Rofes 2007-09-25 09:33:30 0000 -------
I vote NO.

------- Comment #26 From Joshua Kinard 2007-09-28 02:37:45 0000 -------
mips stable.

------- Comment #27 From Raphael Marichez 2007-10-02 21:26:41 0000 -------
we already sent a GLSA for such an issue in the near past (bug #189682 and GLSA
200709-09), and i would send a GLSA here too. I vote yes.

------- Comment #28 From Matt Drew 2007-10-11 21:17:21 0000 -------
I vote yes, because the reasoning is the same as the previous tar
vulnerability.

GLSA request filed.

------- Comment #29 From Sune Kloppenborg Jeppesen 2007-10-14 07:45:08 0000 -------
star is not as widely used as tar that was why I voted NO (rating A4 vs B4).

------- Comment #30 From Raphael Marichez 2007-10-22 22:28:15 0000 -------
glsa 200710-08, thanks everybody

------- Comment #31 From Robert Buchholz 2007-10-22 22:35:40 0000 -------
(In reply to comment #30)
> glsa 200710-08, thanks everybody

Uhh... I'd call it GLSA 200710-23.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug