Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 150289 - x11-libs/lesstif - potential local root vulnerability (CVE-2006-4124)
Summary: x11-libs/lesstif - potential local root vulnerability (CVE-2006-4124)
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B1? [] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-06 08:00 UTC by Carsten Lohrke (RETIRED)
Modified: 2006-11-20 23:39 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2006-10-06 08:00:56 UTC
The libXm library in LessTif 0.95.0 and earlier allows local users to gain privileges via the DEBUG_FILE environment variable, which is used to create world-writable files when libXm is run from a setuid program.


http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4124
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2006-10-11 05:56:20 UTC
donnie, you touched this the last time, could you bump it?
Comment 2 Chris White (RETIRED) gentoo-dev 2006-10-11 07:51:37 UTC
There's currently no known patch for this on upstream sites, or anywhere at all in security sites.  

[07:45] <redpig> it looks like gentoo's build uses --enable-production
[07:46] <redpig> I haven't looked at the source but *supposedly* that'll disable DEBUG_FILE

there's the rare cass that people decide to use EXTRA_ECONF to pass a disable flag in but..  Anyways, until we can get a patch for this one I say mask/punt the sucker.
Comment 3 Donnie Berkholz (RETIRED) gentoo-dev 2006-10-11 09:16:07 UTC
Agree with Chris -- we aren't susceptible. Verified in the source. For anyone else who cares to duplicate, track LESSTIF_PRODUCTION from configure.in to ./include/LTconfig.h.in to ./lib/Xm-2.1/DebugUtil.c.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-20 23:39:28 UTC
I don't think we support all EXTRA_ECONF scenarios so I'm closing this one as invalid.