Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 53399 - net-analyzer/aimsniff symlink attack
Summary: net-analyzer/aimsniff symlink attack
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.aimsniff.com/forum/viewtop...
Whiteboard: B3 [glsa? masked]
Keywords:
: 53905 (view as bug list)
Depends on:
Blocks:
 
Reported: 2004-06-09 05:54 UTC by John Lyon
Modified: 2011-10-30 22:37 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Lyon 2004-06-09 05:54:51 UTC
The aimsniff ebuild, version 0.9, contains a security vulnerability.  Currently, it downloads and installs version 0.9b of aimsniff.  This hole, documented by the aimsniff author in a post to the aimsniff forums at:

http://www.aimsniff.com/forum/viewtopic.php?t=509

Can be fixed by updating the ebuild to download and install version 0.9d of aimsniff.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2004-06-09 06:01:30 UTC
Undisclosed security problem...
ebuild should be updated to use 0.9d.
Comment 2 John Davis (zhen) (RETIRED) gentoo-dev 2004-06-09 08:49:22 UTC
working on it ...
Comment 3 solar (RETIRED) gentoo-dev 2004-06-09 08:52:26 UTC
I think this software should be remove from portage all together.
Whats next 'emerge rootkit'
Comment 4 John Lyon 2004-06-09 08:59:06 UTC
modified the current ebuild and left it on the internet here:

http://www.prism.gatech.edu/~gte481z/aimsniff.html

can not test it now as I am at work.  Will submit an ebuild file and test results when I get back from work tonight.  Anyone who wishes to test the ebuild at that link is welcome.
Comment 5 John Lyon 2004-06-09 09:02:50 UTC
Why remove it from portage?  Aimsniff has legitmate uses such as monitoring employees on company computers to make sure they are not abusing their companies internet use policy or finiancial institutions who are required to log all communication transactions.  It's just a passive network packet sniffer.  Really just a pretty version of tcpdump or ethereal, and not nearly as dangerous as ettercap (also in portage), speaking of "emerge rootkit".
Comment 6 solar (RETIRED) gentoo-dev 2004-06-09 10:18:07 UTC
fair enough.
Comment 7 John Lyon 2004-06-09 17:19:48 UTC
Ebuild sorta seems to work.  I don't have mysql or apache installed on my box at home to really to test it though.  Someone else will need to take it up from here.  I'm leaving the ebuild modifications I made up on the net at the address above.
Comment 8 John Davis (zhen) (RETIRED) gentoo-dev 2004-06-10 07:06:02 UTC
sorry i haven't gotten around to this yet. We lost power all last night and this morning due to storms. I will see if I can get to it today.
Comment 9 John Lyon 2004-06-14 10:29:41 UTC
New Ebuild to plug this whole submitted to bugzilla as bug #53905
Comment 10 Seemant Kulleen (RETIRED) gentoo-dev 2004-06-14 10:56:19 UTC
*** Bug 53905 has been marked as a duplicate of this bug. ***
Comment 11 John Davis (zhen) (RETIRED) gentoo-dev 2004-06-14 14:29:05 UTC
i'm not going to be able to get to this because my releng responsibilities are taking up my time. bug-wranglers?
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2004-06-17 12:50:00 UTC
Vulnerability description available at :
http://www.osvdb.org/displayvuln.php?osvdb_id=6381

We need to find someone to bump or validate the provided ebuild.
Comment 13 Kurt Lieber (RETIRED) gentoo-dev 2004-06-23 12:06:46 UTC
posted a request[1] on gentoo-dev for a dev to take over maintainership of this package.  Nobody responded.  Masking for now.

[1] http://article.gmane.org/gmane.linux.gentoo.devel/19008/
Comment 14 Ian Leitch (RETIRED) gentoo-dev 2004-06-23 13:18:10 UTC
Even though I'd never use such a package, I hate seeing packages masked due to lack of maintainership. I'll take care of the bump, looks like the ebuild could use some love. 
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2004-06-24 01:45:50 UTC
port001 : you're welcome :)
Package has been masked in the meantime, updating status whiteboard.
Comment 16 Ian Leitch (RETIRED) gentoo-dev 2004-06-27 13:52:33 UTC
Bumped ebuild in CVS. Converted the ebuild to use webapp also. 
Comment 17 Thierry Carrez (RETIRED) gentoo-dev 2004-06-28 02:00:43 UTC
PPC : please test and mark the 0.9-r1 ebuild "~ppc" so that we can unmask it.
Comment 18 David Holm (RETIRED) gentoo-dev 2004-06-28 02:18:40 UTC
It has been marked. Since 0.9 was ~ppc you could have keyworded it yourselves, unless there was a specific reason to remove the keyword.
Comment 19 Thierry Carrez (RETIRED) gentoo-dev 2004-06-28 02:55:18 UTC
dholm: would've done it if I had commit access :)
klieber: I think you can unmask the package.

This is ready for a GLSA vote.
Comment 20 Kurt Lieber (RETIRED) gentoo-dev 2004-06-28 08:11:01 UTC
unmasking from package.mask. closing without GLSA since this is a ~masked ebuild.