Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 240546 - www-apps/freeradius-dialupadmin < 1.80 Insecure Temporary Files
Summary: www-apps/freeradius-dialupadmin < 1.80 Insecure Temporary Files
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/32170/
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-08 16:26 UTC by Joel
Modified: 2008-10-12 11:10 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Joel 2008-10-08 16:26:40 UTC
Description:
Some vulnerabilities have been reported in FreeRADIUS, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

The vulnerabilities are caused due to the "dialup_admin/bin/backup_radacct", "dialup_admin/bin/clean_radacct", "dialup_admin/bin/monthly_tot_stats", "dialup_admin/bin/tot_stats", and "dialup_admin/bin/truncate_radacct" scripts handling temporary files in an insecure manner. These can be exploited via symlink attacks to e.g. overwrite arbitrary files with escalated privileges.

The vulnerabilities are reported in version 2.0.4. Other versions may also be affected.

Solution:
Restrict local access to trusted users only.

Original Advisory:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496389
http://uvw.ru/report.lenny.txt
Comment 1 Alin Năstac (RETIRED) gentoo-dev 2008-10-12 10:39:00 UTC
Actually, the vulnerable Gentoo package is www-apps/freeradius-dialupadmin.

Fixed in version 1.80 by applying the tmpfile.patch which is an improvement of the patch made by Pavol Rusnak (see http://bugs.freeradius.org/show_bug.cgi?id=605).

Since this package don't have stable keywords, there is no need to involve arch teams in it.
Comment 2 Christian Hoffmann (RETIRED) gentoo-dev 2008-10-12 11:10:40 UTC
Thanks, populating whiteboard (not exactly sure about "2" though; it's a provilege escalation issue, but not to root, as I get it) and closing then.