Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 199193
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
pam-0.99.7.1-console-decrement.patch pam-0.99.7.1-console-decrement.patch patch Robert Buchholz 2007-11-14 23:39 0000 1.85 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 199193 depends on: Show dependency tree
Bug 199193 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-11-14 23:36 0000
CVE-2007-1716 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1716):
  pam_console does not properly restore ownership for certain console devices
  when there are multiple users logged into the console and one user logs out,
  which might allow local users to gain privileges.

------- Comment #1 From Robert Buchholz 2007-11-14 23:38:54 0000 -------
Pam herd, can you confirm this bug still exists in our version of pam_console?

------- Comment #2 From Robert Buchholz 2007-11-14 23:39:21 0000 -------
Created an attachment (id=136004) [details]
pam-0.99.7.1-console-decrement.patch

Patch applied by RedHat

------- Comment #3 From Diego E. 'Flameeyes' Pettenò 2007-11-15 12:22:05 0000 -------
It has always been the case and it's my main reason for detesting pam_console.

Thank you for giving me the excuse^Wreason to get rid of pam_console entirely
:)

------- Comment #4 From Robert Buchholz 2007-11-15 12:50:11 0000 -------
That is, you advise to mask and last-rite it?

There's no use for it anymore?

------- Comment #5 From Diego E. 'Flameeyes' Pettenò 2007-11-15 12:56:48 0000 -------
My advise would be to cvs rm -f it...
Yes there is still an use case for it, but it's supposedly going to be covered
by consolekit, and there is too much burden with it. I won't maintain
pam_console, I said that already, and I doubt there is anyone else right now
wanting to maintain it. It's defective by design.

------- Comment #6 From Robert Buchholz 2007-11-15 13:06:13 0000 -------
Sounds good, please mask and last-rite then. We'll prepare a mask-glsa as soon
as it's on its way.

------- Comment #7 From Diego E. 'Flameeyes' Pettenò 2007-11-15 13:11:34 0000 -------
There's also the problem that ~sys-libs/pam-0.78 still carries pam_console. If
you're fine with it I'll remove the keywords for all arches but mips (that
hasn't neither ~mipsed nor mipsed 0.99 series - otherwise 0.99 is stable for
all arches).

------- Comment #8 From Robert Buchholz 2007-11-15 16:02:09 0000 -------
sounds good.

------- Comment #9 From Robert Buchholz 2007-11-15 22:41:57 0000 -------
masked, last-rited. and maskglsa filed.

------- Comment #10 From Robert Buchholz 2007-11-16 00:28:38 0000 -------
Rerating B4 as the impact is only information leak.

------- Comment #11 From Robert Buchholz 2007-11-16 00:31:42 0000 -------
Rerating ~4, this was never stable. Let's wait until it's gone then.

------- Comment #12 From Diego E. 'Flameeyes' Pettenò 2007-11-16 10:03:02 0000 -------
sys-libs/pam-0.78 was stable till a few weeks ago.

------- Comment #13 From Robert Buchholz 2007-11-16 14:13:03 0000 -------
Right, since about Oct. 20.

GLSA vote for pam now open. I tend to vote no.

------- Comment #14 From Glynn Clements 2007-11-28 18:04:55 0000 -------
ConsoleKit is not a substitute as it requires X

------- Comment #15 From Diego E. 'Flameeyes' Pettenò 2007-11-28 19:31:12 0000 -------
No it does not. And please leave this bug alone if it has nothing to add to
security team.

------- Comment #16 From Pierre-Yves Rofes 2007-12-10 21:47:13 0000 -------
votin no too, and finally closing, sorry for the delay.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug