Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 111076 - kde-misc/krusader: cleartext passwords stored in krusaderrc
Summary: kde-misc/krusader: cleartext passwords stored in krusaderrc
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.krusader.org/
Whiteboard: B4 [] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-10-31 18:33 UTC by Anonymous bin ich
Modified: 2019-12-01 21:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Anonymous bin ich 2005-10-31 18:33:36 UTC
New updates for Krusader are availble:
Krusader 1.60.1

It fixes a security hole (http://www.krusader.org/phpBB/viewtopic.php?t=1367).

Reproducible: Always
Steps to Reproduce:
1.
2.
3.



Expected Results:  
Please update the portage.
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2005-11-03 06:44:01 UTC
v.1.60.1 is in cvs, please mark stable
Comment 2 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-11-03 11:16:41 UTC
Stable on ppc.
Comment 3 Gustavo Zacarias (RETIRED) gentoo-dev 2005-11-03 13:10:08 UTC
sparc stable.
Comment 4 Mark Loeser (RETIRED) gentoo-dev 2005-11-03 22:51:50 UTC
obj /var/tmp/portage/krusader-1.60.1/image/usr/share/apps/krusader/krusaderui.rc
5df09f91682fe7e9024ae654224fa1bc 1131095046

The install of this is slightly screwed up.  Its putting stuff in the tmpdir.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-11-04 00:39:27 UTC
Back to ebuild status, waiting for Carsten to have a look.
Comment 6 Gregorio Guidi (RETIRED) gentoo-dev 2005-11-05 10:04:44 UTC
The solution is to readd the src_compile snippet that was present in 0.60.0. 
Do you want a revision bump for that? 
 
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-11-05 11:06:58 UTC
Both are fixed from security's point of view, no revbump needed on our side.
Your call, really.
Comment 8 Gregorio Guidi (RETIRED) gentoo-dev 2005-11-05 14:07:28 UTC
The problem in comment #4 is now fixed in 1.60.1. 
 
Comment 9 Mark Loeser (RETIRED) gentoo-dev 2005-11-05 21:47:25 UTC
Thanks, x86 stable
Comment 10 Homer Parker (RETIRED) gentoo-dev 2005-11-09 10:33:40 UTC
Didn't go so well on my system..

[ebuild  N    ] kde-misc/krusader-1.60.1  +arts -debug -javascript +kde
+kdeenablefinal -xinerama 0 kB

Resulted in:

x86_64-pc-linux-gnu-g++ -DHAVE_CONFIG_H -I. -I. -I.. -I/usr/kde/3.4/include
-I/usr/qt/3/include -I.   -DQT_THREAD_SUPPORT  -D_REENTRANT
-D_LARGEFILE64_SOURCE -DKDE_NO_COMPAT -DQT_NO_ASCII_CAST  -Wnon-virtual-dtor
-Wno-long-long -Wundef -ansi -D_XOPEN_SOURCE=500 -D_BSD_SOURCE -Wcast-align
-Wconversion -Wchar-subscripts -Wall -W -Wpointer-arith -Wwrite-strings -DNDEBUG
-DNO_DEBUG -O2 -march=k8 -fomit-frame-pointer -Os -pipe -Wformat-security
-Wmissing-format-attribute -fno-exceptions -fno-check-new -fno-common -c -o
main.o `test -f 'main.cpp' || echo './'`main.cpp
panelmanager.cpp:284:28: panelmanager.moc: No such file or directory
paneltabbar.cpp:262:27: paneltabbar.moc: No such file or directory
make[3]: *** [panelmanager.o] Error 1
make[3]: *** Waiting for unfinished jobs....
make[3]: *** [paneltabbar.o] Error 1
make[3]: Leaving directory
`/var/tmp/portage/krusader-1.60.1/work/krusader-1.60.1/krusader'
make[2]: *** [all-recursive] Error 1
make[2]: Leaving directory
`/var/tmp/portage/krusader-1.60.1/work/krusader-1.60.1/krusader'
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/var/tmp/portage/krusader-1.60.1/work/krusader-1.60.1'
make: *** [all] Error 2

!!! ERROR: kde-misc/krusader-1.60.1 failed.
!!! Function kde_src_compile, Line 168, Exitcode 2
!!! died running emake, kde_src_compile:make
!!! If you need support, post the topmost build error, NOT this status message.

emerge --info
Portage 2.0.51.22-r3 (default-linux/amd64/2005.1, gcc-3.4.4, glibc-2.3.5-r2,
2.6.13-ck8 x86_64)
=================================================================
System uname: 2.6.13-ck8 x86_64 AMD Athlon(tm) 64 Processor 3400+
Gentoo Base System version 1.6.13
distcc 2.18.3 x86_64-pc-linux-gnu (protocols 1 and 2) (default port 3632) [disabled]
dev-lang/python:     2.3.5-r2, 2.4.2
sys-apps/sandbox:    1.2.12
sys-devel/autoconf:  2.13, 2.59-r6
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r1
sys-devel/binutils:  2.15.92.0.2-r10
sys-devel/libtool:   1.5.20
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS="amd64"
AUTOCLEAN="yes"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=k8 -fomit-frame-pointer -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/2/share/config /usr/kde/3.4/env
/usr/kde/3.4/share/config /usr/kde/3.4/shutdown /usr/kde/3/share/config
/usr/lib/X11/xkb /usr/lib64/mozilla/defaults/pref /usr/share/config
/usr/share/texmf/dvipdfm/config/ /usr/share/texmf/dvips/config/
/usr/share/texmf/tex/generic/config/ /usr/share/texmf/tex/platex/config/
/usr/share/texmf/xdvi/ /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/gconf /etc/terminfo /etc/env.d"
CXXFLAGS="-march=k8 -fomit-frame-pointer -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig collision-protect cvs distlocks fixpackages multilib-strict
sandbox sfperms strict test"
GENTOO_MIRRORS="ftp://gentoo.netnitco.net/pub/mirrors/gentoo/source/
ftp://mirrors.tds.net/gentoo ftp://gentoo.ccccom.com"
LC_ALL="en_US.UTF-8"
MAKEOPTS="-j3"
PKGDIR="/usr/portage/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="amd64 X a52 aac acpi alsa apache2 arts audiofile avi bash-completion berkdb
bitmap-fonts browserplugin bzip2 cdr crosscompile crypt cups curl dbus dri dv
dvd dvdr eds emboss emul-linux-x86 encode ethereal exif expat fam ffmpeg flac
foomaticdb ftp gd gif glut glx gnome gnutls gpm gstreamer gtk gtk2 gtkhtml hal
idn ieee1394 imap imlib java javacomm javamail jikes jpeg junit kde
kdeenablefinal lcms ldap libwww lirc lm_sensors lzo lzw lzw-tiff mad memlimit
mmap mng mozilla moznocompose moznoirc moznomail mozsvg mp3 mpeg mpi ncurses nfs
nls noplugin nptl nptlonly offensive ogg opengl pam pcntl pcre pda pdflib perl
png postgres python quicktime readline sdl sharedmem snmp sockets spell ssl svg
sysvipc tcltk tetex tiff truetype truetype-fonts type1-fonts udev unicode usb
userlocales vim-with-x vorbis webdav xerces xface xml xml2 xmlrpc xmms xpm
xprint xv zlib userland_GNU kernel_linux elibc_glibc"
Unset:  ASFLAGS, CTARGET, LANG, LDFLAGS, LINGUAS
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-09 11:45:12 UTC
Back to ebuild. We need a patch for amd64. 
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-14 14:10:21 UTC
kde/amd64 can any of you provide a patch for this problem? 
Comment 13 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-19 14:10:20 UTC
krusaderrc is of course stored in ~ so this is really no security issue.  
  
Sorry for the noise.