Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 163787 - SECURITY: app-admin/rmake does not drop supplemental group permissions: CVE-2007-0536
Summary: SECURITY: app-admin/rmake does not drop supplemental group permissions: CVE-2...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Jonathan Smith (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-01-25 18:19 UTC by Jonathan Smith (RETIRED)
Modified: 2007-01-29 19:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jonathan Smith (RETIRED) gentoo-dev 2007-01-25 18:19:24 UTC
upstream bug report: https://issues.rpath.com/browse/RPL-987

A weakness in the rMake build tool could allow for a local user root privilege escalation.
Comment 1 Jonathan Smith (RETIRED) gentoo-dev 2007-01-25 18:27:44 UTC
Note that app-admin/rmake has never had a stable version in portage, so a GLSA is not necessary.
Comment 2 Jonathan Smith (RETIRED) gentoo-dev 2007-01-27 23:06:38 UTC
This issue has been assigned CVE-2007-0536
Comment 3 Jonathan Smith (RETIRED) gentoo-dev 2007-01-29 16:31:00 UTC
rMake 1.0.4 has been released to address this issue.
Comment 4 Jonathan Smith (RETIRED) gentoo-dev 2007-01-29 16:38:49 UTC
fixed
Comment 5 Jonathan Smith (RETIRED) gentoo-dev 2007-01-29 19:46:18 UTC
btw, my update also fixes upstream bug https://issues.rpath.com/browse/RPL-1002