Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 45961 - Systrace: systrace silently patches full local bypass vulnerability on Linux
Summary: Systrace: systrace silently patches full local bypass vulnerability on Linux
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: GLSA Errors (show other bugs)
Hardware: All Linux
: High critical (vote)
Assignee: Gentoo Security
URL: http://seclists.org/lists/fulldisclos...
Whiteboard:
Keywords:
: 48080 (view as bug list)
Depends on:
Blocks:
 
Reported: 2004-03-28 02:40 UTC by Tobias Weisserth
Modified: 2004-04-18 03:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Weisserth 2004-03-28 02:40:00 UTC
See URL for a very detailed description.

Reproducible: Always
Steps to Reproduce:
Comment 1 Daniel Brandt 2004-03-28 04:25:43 UTC
This is ugly.. 

systrace is masked ~x86 and it's still at version 1.0 in portage, version 1.5 was released on 2004-01-26 according to systrace.org.. 

Should the claims of the publisher of the email be true (the part in the "executive summary", specifically), and seeing that it's still version 1.0 (and obviously not widely used since it's still marked ~), it should be removed from portage all together.
Comment 2 solar (RETIRED) gentoo-dev 2004-03-28 10:56:44 UTC
I'd opt for removal/masking..

We lost the maintainer (natey) some time ago and nobody has even requested 
anything in regards to systrace in many months, not even a version bump 
that I'm aware of..
Comment 3 solar (RETIRED) gentoo-dev 2004-03-28 11:21:36 UTC
I did find one thing in portage which has never been resolved.
http://bugs.gentoo.org/show_bug.cgi?id=35896
Comment 4 Joshua Brindle (RETIRED) gentoo-dev 2004-03-28 11:57:29 UTC
hardened no longer supports systrace because of other issues like this one, If noone says otherwise i'll remove it from portage in 24 hours
Comment 5 Joshua Brindle (RETIRED) gentoo-dev 2004-03-28 15:16:21 UTC
CCing x86-kernel so that they know to remove systrace from gentoo-sources
Comment 6 Joshua Brindle (RETIRED) gentoo-dev 2004-03-29 15:47:36 UTC
sys-apps/systrace and sys-apps/gtk-systrace removed from portage
gentoo-sources still needs to remove systrace from kernels
i don't see evidence that systrace is applied to any other kernels
Comment 7 Joshua Brindle (RETIRED) gentoo-dev 2004-03-29 15:55:55 UTC
gentoo-sources devs, since gentoo-sources is the most used kernel (probably) and we have no way of telling who might have enabled systrace support even unknowingly do you think it's a good idea to release a GLSA?
Comment 8 Brian Jackson (RETIRED) gentoo-dev 2004-03-29 16:08:21 UTC
x86-kernel is maintaining gentoo-sources now. afaic, all 2.4.22-gentoo kernels can be removed from portage. I'm sure plasmaroo won't disagree.
Comment 9 Tim Yamin (RETIRED) gentoo-dev 2004-03-30 08:00:58 UTC
Since it is patched upstream in 2.4.25 and 2.4.25 is stable; no, I don't really see the point of a GLSA.
Comment 10 Thierry Carrez (RETIRED) gentoo-dev 2004-04-07 08:41:23 UTC
Changing product to GLSA for discussion on how appropriate a GLSA is on the subject.
Comment 11 Joshua Brindle (RETIRED) gentoo-dev 2004-04-07 13:55:03 UTC
As the vulnerable part of systrace was in the kernel, and the kernels haven't had systrace patches for quite some time I agree with tim and brian about the non-necessity of a glsa
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2004-04-08 01:17:38 UTC
Closing without GLSA, as systrace is no longer supported.
-K
Comment 13 Martin Holzer (RETIRED) gentoo-dev 2004-04-18 03:13:24 UTC
*** Bug 48080 has been marked as a duplicate of this bug. ***