Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 345567 (CVE-2010-3998) - <media-sound/banshee-1.8.0-r1: Insecure LD_LIBRARY_PATH Processing (CVE-2010-3998)
Summary: <media-sound/banshee-1.8.0-r1: Insecure LD_LIBRARY_PATH Processing (CVE-2010-...
Status: RESOLVED FIXED
Alias: CVE-2010-3998
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://download.banshee.fm/banshee/un...
Whiteboard: B4 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-11-15 05:03 UTC by Tim Sammut (RETIRED)
Modified: 2014-02-05 11:10 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2010-11-15 05:03:45 UTC
From the NVD, http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3998:

The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Comment 1 Arun Raghavan (RETIRED) gentoo-dev 2010-11-15 05:37:42 UTC
Added upstream patch to fix this [1] in 1.8.0-r1 and removed 1.8.0 from tree. Is there anything else that needs to be done to mark this fixed?

[1] http://git.gnome.org/browse/banshee/commit/?h=stable-1.8&id=835c37e99196303195c88932169b73e975115e52
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2010-11-15 05:44:37 UTC
Great, thank you, Arun. We also need to do stabilization, and since this is a security bug, we keep it open until we either publish a GLSA or decide we are not going to.

Arches, please test and mark stable:
=media-sound/banshee-1.8.0-r1
Target keywords : "amd64 x86"
Comment 3 Pacho Ramos gentoo-dev 2010-11-15 09:47:12 UTC
Also:
=media-plugins/banshee-community-extensions-1.8.0

will need to go stable as current stable doesn't work with banshee-1.8
Comment 4 Thomas Kahle (RETIRED) gentoo-dev 2010-11-15 12:47:27 UTC
(In reply to comment #3)
> =media-plugins/banshee-community-extensions-1.8.0

This has a missing dependency  

lirc? ( app-misc/lirc )

Otherwise all fine. I'm ready to go on x86 as soon as you added it or told me to do it myself.

Comment 5 Pacho Ramos gentoo-dev 2010-11-15 13:06:56 UTC
(In reply to comment #4)
> Otherwise all fine. I'm ready to go on x86 as soon as you added it or told me
> to do it myself.
> 

Please add it yourself as I don't have much time right now (and thanks a lot for finding that missing dep)
Comment 6 Thomas Kahle (RETIRED) gentoo-dev 2010-11-15 13:19:57 UTC
Dependency added, x86 done. 
Comment 7 Agostino Sarubbo gentoo-dev 2010-11-16 17:07:12 UTC
ok on amd64!
Comment 8 Markos Chandras (RETIRED) gentoo-dev 2010-11-17 20:58:40 UTC
(In reply to comment #3)
> Also:
> =media-plugins/banshee-community-extensions-1.8.0
> 
> will need to go stable as current stable doesn't work with banshee-1.8
> 

amd64 done. Thanks Agostino. 

@Pacho

why don't you force this version inside the banshee ebuild?
Comment 9 Tim Sammut (RETIRED) gentoo-dev 2010-11-17 21:11:05 UTC
Thanks, folks.

GLSA Vote: Yes.
Comment 10 Stefan Behte (RETIRED) gentoo-dev Security 2010-11-21 16:54:08 UTC
Vote: YES, glsa request filed.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 19:56:41 UTC
CVE-2010-3998 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3998):
  The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier
  place a zero-length directory name in the LD_LIBRARY_PATH, which allows
  local users to gain privileges via a Trojan horse shared library in the
  current working directory.  NOTE: Banshee might also be affected using
  GST_PLUGIN_PATH.
Comment 12 Justin Lecher (RETIRED) gentoo-dev 2013-10-08 13:47:31 UTC
That version seems to be gone for a long time.
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2014-02-05 11:10:03 UTC
This issue was resolved and addressed in
 GLSA 201402-05 at http://security.gentoo.org/glsa/glsa-201402-05.xml
by GLSA coordinator Sergey Popov (pinkbyte).