Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 147197 - app-editors/bluefish can crash X server
Summary: app-editors/bluefish can crash X server
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-09-11 08:06 UTC by Yuriy Dmitriev
Modified: 2007-03-30 20:45 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Yuriy Dmitriev 2006-09-11 08:06:58 UTC
This critical bug may be exploited to access root account.

I test it on gentoo 3 machines (arch i386), latest updates, eg --sync now.

Step to reproduce:

1. install xorg-x11 modular latest stable in portage. 
2. install html editor bluefish (stable in portage)
3. install firefox (stable in portage)
4. enable in firefox javascript
5. open url http://maps.google.com in firefox
6. save requested front page to some location
7. remove folder http_name.files with images
8. open bluefish
9. in bluefish, select file-open and secect saved html page from maps.google.com
10. RESULT = CRASH X server.


 I think, this bug may have root exploit, as I know, xorg run as root. Initialy bug present in bluefish, of course, but xorg API MUST corect resolve incorrect API calls, but do nothing :(

Sorry, I do not have time to find bug in sourse code :( too many work :(:(


 And, I must WARN gentoo community about this...

With best whishes - triod.
Comment 1 Yuriy Dmitriev 2006-09-11 08:11:12 UTC
No Additional Comments
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-09-11 10:04:27 UTC
Oh, that's really "easily" abused, just have to induce someone to do 10 steps including installing multiple apps... Security doesn't handle such stuff at all AFAIK, should be reassigned to maintainer.
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-10-17 13:24:21 UTC
is this reproductible for someone else ?
Comment 4 Chris White (RETIRED) gentoo-dev 2006-10-17 13:53:00 UTC
I can't reproduce it, but it does cause bluefish to get a very high load, so the best I could think of "security wise" was that it would cause oom killer to go nuts and DoS things.  However, this would only really be applicable to a desktop environment, so if you're running mission critical server applications on a desktop system, well yah...

So, that's about that :P.
Comment 5 Wolf Giesen (RETIRED) gentoo-dev 2006-10-17 14:05:23 UTC
What's high load got to do with oom killer, anyway?

Besides that, good luck in hunting this one down. Way to many components involved. It might actually be a real issue, but I don't see us having the resources to even remotely track it down :/
Comment 6 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-10-25 06:56:36 UTC
Yuriy, do you have an nvidia card ?
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-30 20:45:00 UTC
Closing this one as INVALID for now. Feel free to reopen if you have further information.