Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 125075 - media-sound/teamspeak2-server-bin: insecure permissions of server.log
Summary: media-sound/teamspeak2-server-bin: insecure permissions of server.log
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL:
Whiteboard: B4 [tomask] DerCorny
Keywords:
Depends on:
Blocks:
 
Reported: 2006-03-05 05:46 UTC by lefti
Modified: 2006-04-01 07:59 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description lefti 2006-03-05 05:46:56 UTC
Hi, there is bad permission of /var/log/teamspeak2-server/server.log file. This file is no-reasonably world-readable
Comment 1 lefti 2006-03-05 05:48:08 UTC
And in this file is printed password of ts2 (super)admin.
Comment 2 Jeremy Huddleston (RETIRED) gentoo-dev 2006-03-31 22:43:17 UTC
This is a binary package, and the file isn't installed by us.  This file is created by the application.  Please report this upstream
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-03-31 22:46:24 UTC
lefti will you report it upstream or should the Security Team handle it?
Comment 4 lefti 2006-04-01 03:46:51 UTC
TS2 developers said me "This isn't bug".
Comment 5 schaedpq 2006-04-01 04:08:15 UTC
Mhmm. World-readable admin password is not a bug, did I get that right? Mhmm. Impressive. In that case, I am quite happy, that I don't have that software on my machines.
Comment 6 Stefan Cornelius (RETIRED) gentoo-dev 2006-04-01 06:26:27 UTC
not a bug for them, but I still don't like that. Since its a binary package, we probably have no possibilities to fix this on our own. What about masking it until they change their opinion?
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-04-01 06:39:34 UTC
I agree on masking this one.
Comment 8 schaedpq 2006-04-01 06:41:06 UTC
Well, I am not in the security team and no developer. But I also don't like that and think, that (potential) users should be warned about that password disclosure.
Masking the package until the problem is solved seems to be the best way (available for Gentoo) do deal with the problem, I believe.
Comment 9 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-04-01 07:51:55 UTC
(In reply to comment #5)
> Impressive.

Yes !

maybe it comes from :
    einfo "The Teamspeak Server generates the admin and superadmin"
    einfo "passwords on the fly.  To get them, please look in:"
    einfo "/var/log/teamspeak2-server/server.log"

but since the one who installs the soft (and start it) should be the root, this is completely unuseful...

Will try to find a workaround but not sure to fulfil it :)
Comment 10 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-04-01 07:55:14 UTC
Some news here.

I installed the soft, and it reveals than the logfile is NOT world-readable :

$ lld /var/log/teamspeak2-server
drwx------  2 teamspeak2 root 104 Apr  1 17:53 /var/log/teamspeak2-server

It is not a security issue as for me.
Comment 11 Tavis Ormandy (RETIRED) gentoo-dev 2006-04-01 07:59:29 UTC
This looks INVALID, please reopen if you disagree.

Thanks Raphael.