Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 83165 - app-i18n/uim: Possible privilege escalation through linked setuid/setgid apps
Summary: app-i18n/uim: Possible privilege escalation through linked setuid/setgid apps
Status: RESOLVED DUPLICATE of bug 82678
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Bryan Østergaard (RETIRED)
URL: http://lists.freedesktop.org/pipermai...
Whiteboard: B2? [stable]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-02-24 02:40 UTC by Thierry Carrez (RETIRED)
Modified: 2019-09-23 07:23 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-02-24 02:40:08 UTC
uim 0.4.5.1 is released. This release is for *security fix*.

 http://uim.freedesktop.org/releases/uim-0.4.5.1.tar.gz
 sha1sum:4a113fc3472fdf7561eb2ad57af189f94a7b17ee  uim-0.4.5.1.tar.gz

All uim except 0.4.5.1 and 0.4.6beta1 have a security hole.

If you are using 'immodule for Qt' enabled Qt, you should upgrade your 
uim to 0.4.5.1 or 0.4.6beta1. (We'll release 0.4.6beta1 ASAP.)

Brief of the bug
================

Vulnerability  : privilege escalation
Problem-Type   : local

Takumi ASAKI discovered that uim always trusts environment variables. 
But this is not correct behavior, sometimes environment variables 
shouldn't be trusted. This bug causes privilege escalation when libuim 
is linked against setuid/setgid application. Since GTK+ prohibits 
setuid/setgid applications, the bug appears only in 'immodule for Qt' 
enabled Qt. (Normal Qt is also safe.)
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-02-24 02:42:37 UTC
This is CAN-2005-0503
0.4.5.1 is already in the tree, needing stable keywords from alpha, amd64, ppc.
Comment 2 Jochen Maes (RETIRED) gentoo-dev 2005-02-24 02:54:42 UTC
testing on ppc
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-02-24 02:58:37 UTC
Sorry for the dupe, please ignore this bug

*** This bug has been marked as a duplicate of 82678 ***
Comment 4 Jochen Maes (RETIRED) gentoo-dev 2005-02-24 03:00:29 UTC
stable on ppc