First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 78230
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
CAN-2005-0071.patch CAN-2005-0071.patch patch Sune Kloppenborg Jeppesen 2005-01-16 08:49 0000 1.03 KB Details | Diff
vdr-1.2.6_CAN-2005-0071.patch vdr-1.2.6_CAN-2005-0071.patch patch Thierry Carrez (RETIRED) 2005-01-24 05:38 0000 893 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 78230 depends on: Show dependency tree
Bug 78230 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-01-16 08:47 0000
Javier Fern

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-01-16 08:47:37 0000 -------
Javier Fernández-Sanguino Peña from the Debian Security Audit Team has
discovered that the vdr daemon which is used for video disk recorders
for DVB cards can overwrite arbitrary files.

Not sure if one of you has vdr running as root as well, but we had
this situation in our slightly old stable release.  If it is running
as a separate user, you're fine.  If it is running as root, the
attached patch will fix this problem.

Please let me know if you require coordination with this vulnerability.

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-01-16 08:49:27 0000 -------
Created an attachment (id=48663) [details]
CAN-2005-0071.patch

------- Comment #3 From Chris White (RETIRED) 2005-01-17 10:32:35 0000 -------
I'm really not sure on this one, as the conditions seem pretty pathetic to
execute this bug.  I mean.. if the person has root access, wth, who needs vdr
to remove aribtrary files :|.  You just rm -rf / and you're caused more damage
than this will ever cause.  Maybe it's just me.. but it seems like you'd have
to be some sort of computer macochist(sp?) to actually do damage with this. 
I'll apply the patch shortly though just to make people happy...

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-01-17 14:44:18 0000 -------
I guess a malicious user theoretically could control the DVB input for dvr and
thus exploit this vulnerability.

------- Comment #5 From Thierry Carrez (RETIRED) 2005-01-18 01:13:03 0000 -------
Looks like Debian is affected because they are starting the vdr daemon as root.
My question is, do we have an rc-script to run that daemon at startup ? If so,
does it make use of the root user or a specific user ?

If we don't provide init scripts to run it as startup or if those init scripts
use a specific user, then I think it's shallow and should be dropped. But if
like Debian we provide an init script to start it on startup as root, then we
should probably fix...

I didn't manage to install it on my amd64 (pulls weird depends) so I couldn't
test it. Hope someone else will be able to answer that question. From what
Chris says I understand it's not automatically started so perhaps it's just
better to ignore this.

------- Comment #6 From Thierry Carrez (RETIRED) 2005-01-24 05:38:22 0000 -------
Created an attachment (id=49363) [details]
vdr-1.2.6_CAN-2005-0071.patch

Current patch does not apply to 1.2.6 (filenames changed).
Here is a patch adapted for VDR 1.2.6, untested.

------- Comment #7 From Thierry Carrez (RETIRED) 2005-01-24 05:39:59 0000 -------
I think this applies to us because "runvdr" runs as root by default.
Given the scope it's probably better to wait for this to be public.

------- Comment #8 From Thierry Carrez (RETIRED) 2005-01-25 08:06:33 0000 -------
Public now: Debian Security Advisory DSA 656-1
Unclassified signoff:koon/jaervosz

media-video herd, please apply attached patch

------- Comment #9 From Jan Brinkmann (RETIRED) 2005-01-25 08:15:45 0000 -------
tested and commited.

------- Comment #10 From Thierry Carrez (RETIRED) 2005-01-27 06:53:03 0000 -------
luckyduck/media-video: please create a new revision for the ebuilds, so that
people with vdr installed can get the fix by upgrading.

------- Comment #11 From Jan Brinkmann (RETIRED) 2005-01-27 07:09:12 0000 -------
ok, done

------- Comment #12 From Thierry Carrez (RETIRED) 2005-01-27 07:16:31 0000 -------
GLSA vote. We issue GLSAs for tmpfile vulns and Debian issued one, so I vote
YES.

------- Comment #13 From Sune Kloppenborg Jeppesen 2005-01-29 02:22:13 0000 -------
I vote YES to this one as well.

------- Comment #14 From Thierry Carrez (RETIRED) 2005-01-30 10:51:12 0000 -------
GLSA 200501-42

First Last Prev Next    No search results available      Search page      Enter new bug