Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 235055 (CVE-2005-4458) - www-apps/metadot <6.4.5 Privilege escalation (CVE-2005-4458)
Summary: www-apps/metadot <6.4.5 Privilege escalation (CVE-2005-4458)
Status: RESOLVED FIXED
Alias: CVE-2005-4458
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://osvdb.org/22014
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-08-17 23:47 UTC by Robert Buchholz (RETIRED)
Modified: 2008-08-24 21:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-08-17 23:47:11 UTC
CVE-2005-4458 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2005-4458):
  Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset
  the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing
  checks for special privileges, which allows users to gain administrator
  privileges by adding themselves to the SITE_MGR group.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-08-17 23:47:50 UTC
Arches, please test and mark stable:
=www-apps/metadot-6.4.5.4
Target keywords : "ppc"
Comment 2 Tobias Scherbaum (RETIRED) gentoo-dev 2008-08-19 21:19:49 UTC
ppc stable
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-08-19 22:32:02 UTC
The bug is from 2005, and it was only stable on PPC. No offense to the PPC architecture, but I wonder if it's worth a GLSA where most people would probably use it on x86, and it's ~arch there.

My vote is NO.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-08-24 21:33:28 UTC
(In reply to comment #3)
> The bug is from 2005, and it was only stable on PPC. No offense to the PPC
> architecture, but I wonder if it's worth a GLSA where most people would
> probably use it on x86, and it's ~arch there.
> 
> My vote is NO.
> 

Agreed, voting NO too and closing.