Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 86686
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jean-François Brunette (RETIRED) <formula7@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 86686 depends on: Show dependency tree
Bug 86686 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-03-25 10:38 0000
Description:
Gangstuck and Psirac have reported some vulnerabilities in openMosixview, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges.

The vulnerabilities are caused due to various temporary files being created insecurely with predictable filenames. This can be exploited via symlink attacks to create or overwrite arbitrary files on the system with the privileges of the user running openmosixview or the openmosixcollector daemon.

The vulnerabilities have been reported in versions 1.5 and prior.

Solution:
Grant only trusted users access to affected systems

------- Comment #1 From Matthias Geerdsen 2005-03-25 11:02:23 0000 -------
http://www.securityfocus.com/archive/1/394282

------- Comment #2 From Thierry Carrez (RETIRED) 2005-04-08 08:08:32 0000 -------
See discussion about this bug at:
http://sourceforge.net/mailarchive/forum.php?thread_id=6929877&forum_id=1042

Patches are at:
http://uw-dig.uwaterloo.ca/~hy3chan/patches/openmosixview/1.5/20logdirectory.diff
http://uw-dig.uwaterloo.ca/~hy3chan/patches/openmosixview/1.5/50nonodestmp.diff

tantive/cluster: please review patches and bump with them if you think they are ok.

------- Comment #3 From Thierry Carrez (RETIRED) 2005-04-13 08:32:05 0000 -------
xmerlin (cluster herd) said he would have a look.

------- Comment #4 From Christian Zoffoli 2005-04-15 09:17:53 0000 -------
fixed in cvs

------- Comment #5 From Thierry Carrez (RETIRED) 2005-04-15 10:10:54 0000 -------
Reopening to handle stable/glsa steps

------- Comment #6 From Thierry Carrez (RETIRED) 2005-04-16 04:32:55 0000 -------
xmerlin: could you bump the revision ?

------- Comment #7 From Christian Zoffoli 2005-04-16 06:01:51 0000 -------
done

------- Comment #8 From Thierry Carrez (RETIRED) 2005-04-16 06:52:03 0000 -------
Security please vote on GLSA need

------- Comment #9 From Thierry Carrez (RETIRED) 2005-04-19 00:31:36 0000 -------
Do openmosixview or the openmosixcollector daemon typically run as root ? If
yes, I would issue a GLSA about it, if not, I wouldn't.

xmerlin/cluster herd, could you give us your opinion ?

------- Comment #10 From Thierry Carrez (RETIRED) 2005-04-19 11:23:04 0000 -------
I think it can be run by root quite usually, so I vote YES.

------- Comment #11 From Christian Zoffoli 2005-04-19 12:13:32 0000 -------
It needs to be run as root as I can remember

------- Comment #12 From Sune Kloppenborg Jeppesen 2005-04-19 12:29:31 0000 -------
I vote yes as well.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-04-21 06:57:29 0000 -------
GLSA 200504-20

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug