First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 55675
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 55675 depends on: Show dependency tree
Bug 55675 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-06-30 06:23 0000
From Shorewall's Tom Eastep :

"Javier Fern

------- Comment #1 From Thierry Carrez (RETIRED) 2004-06-30 06:23:01 0000 -------
From Shorewall's Tom Eastep :

"Javier Fernández-Sanguino Peña has discovered an exploitable 
vulnerability in the way that Shorewall handles temporary files and 
directories. The vulnerability can allow a non-root user to cause 
arbitrary files on the system to be overwritten. LEAF Bering and Bering 
uClibc users are generally not at risk due to the fact that LEAF boxes 
do not typically allow logins by non-root users.

For 2.0 users, the problem is corrected in version 2.0.3a:

	http://shorewall.net/pub/shorewall/shorewall-2.0.3a
	ftp://shorewall.net/pub/shorewall/shorewall-2.0.3a

For 1.4 users, the correct version is:

	http://shorewall.net/pub/shorewall/shorewall-1.4.10f
	ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f

I would appreciate immediate feedback on the 1.4.10f version; given that 
I don't have any 1.4 systems remaining, I couldn't fully test that code."

------- Comment #2 From Thierry Carrez (RETIRED) 2004-06-30 06:24:29 0000 -------
Martin : could you have a look and bump accordingly ?

------- Comment #3 From Martin Holzer (RETIRED) 2004-07-01 05:16:51 0000 -------
2.0.3a and 1.4.10f are in cvs

adding arch-maintainers to mark at least 1.4.10f stable.

------- Comment #4 From Thierry Carrez (RETIRED) 2004-07-01 06:25:14 0000 -------
Thanks Martin.
alpha,ppc,x86,sparc : please test and mark 1.4.10f stable.

------- Comment #5 From Bryan Østergaard (RETIRED) 2004-07-02 16:20:58 0000 -------
1.4.10f marked stable on alpha.

------- Comment #6 From Jason Wever (RETIRED) 2004-07-03 11:47:08 0000 -------
Stable on sparc.

------- Comment #7 From Sune Kloppenborg Jeppesen 2004-07-05 14:08:18 0000 -------
GLSA drafted: security please review.

------- Comment #8 From Thierry Carrez (RETIRED) 2004-07-08 02:21:46 0000 -------
GLSA is ready. The ebuild has now x86 stable. 
We're just waiting for ppc to test and mark 1.4.10f stable to publish the GLSA.

------- Comment #9 From Luca Barbato 2004-07-08 08:13:34 0000 -------
Merked ppc

------- Comment #10 From Thierry Carrez (RETIRED) 2004-07-08 09:23:45 0000 -------
Thanks !
It's now ready to send.

------- Comment #11 From Thierry Carrez (RETIRED) 2004-07-08 10:27:12 0000 -------
GLSA 200407-07

First Last Prev Next    No search results available      Search page      Enter new bug