Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 201242 - net-analyzer/zabbix < 1.4.2-r1 UserParameter privilege escalation (CVE-2007-6210)
Summary: net-analyzer/zabbix < 1.4.2-r1 UserParameter privilege escalation (CVE-2007-6...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://bugs.debian.org/cgi-bin/bugrep...
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-12-04 16:02 UTC by Robert Buchholz (RETIRED)
Modified: 2007-12-09 22:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-12-04 16:02:43 UTC
CVE-2007-6210 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6210):
  zabbix_agentd 1.1.4 in ZABBIX runs "UserParameter" scripts with gid 0, which
  might allow local users to gain privileges.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-12-04 16:05:22 UTC
I assume other versions than mentioned in the tree are also affected.

Wolfram, please advise.
Comment 2 Wolfram Schlich (RETIRED) gentoo-dev 2007-12-04 17:14:09 UTC
I have switched net-analyzer/zabbix-{agent,frontend,server}
to net-analyzer/zabbix (with some USE flags) a while ago,
and net-analyzer/zabbix-1.4.2-r1 already contains a fix.

There is an issue with the new-style single zabbix package though,
as it depends on webapp-config due to webapp.eclass inheritance
(because of the web frontend) -- people tend to dislike having to
install webapp-config on a machine where they only want to install
the agent (using USE="agent -frontend -server").

Well. I don't really want to update the old ebuilds now, but I'm
not sure whether it's the best idea to force their users to the
new one either :o)
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2007-12-04 18:06:24 UTC
Thanks a lot, closing then.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-12-04 18:13:15 UTC
(In reply to comment #2)
> Well. I don't really want to update the old ebuilds now, but I'm
> not sure whether it's the best idea to force their users to the
> new one either :o)
 
Well, it's an ~arch ebuild. No need to support older versions :-)

If it works better for you, adding one dependency should not be a problem.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2007-12-09 22:49:48 UTC
Oh, one question left: When will the old style zabbix go away and how do you get users to migrate?