Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 389125 (CVE-2011-4091) - <net-libs/net6-1.3.14 Two Weaknesses (CVE-2011-{4091,4093})
Summary: <net-libs/net6-1.3.14 Two Weaknesses (CVE-2011-{4091,4093})
Status: RESOLVED FIXED
Alias: CVE-2011-4091
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/46605/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-31 18:40 UTC by Agostino Sarubbo
Modified: 2014-02-13 15:09 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-10-31 18:40:43 UTC
Description:
1) The library may perform certain actions prior to validating the authentication of a connecting user, which can be exploited to e.g. disclose certain information about already connected users.

2) It's possible to cause an internal ID counter to overflow, which can be exploited to e.g. hijack another user's session.

The weaknesses are reported in version 1.3.13. Other versions may also be affected.


Solution:
Fixed in the GIT repository.
Comment 1 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-10-31 20:36:11 UTC
+*net6-1.3.14 (31 Oct 2011)
+
+  31 Oct 2011; Kacper Kowalik <xarthisius@gentoo.org> -net6-1.3.13.ebuild,
+  -files/net6-1.3.13-gnutls3.patch, +net6-1.3.14.ebuild:
+  Version bump, contains fixes for CVE-2011-4093 and CVE-2011-4091, drop old

@security:
ready for arches to be cc'ed
Comment 2 Agostino Sarubbo gentoo-dev 2011-10-31 23:22:27 UTC
Thanks.

Arches, please test and mark stable:
=net-libs/net6-1.3.14
target KEYWORDS="amd64 hppa ppc x86"
Comment 3 Agostino Sarubbo gentoo-dev 2011-10-31 23:23:11 UTC
00:22 <ago> rdep net6
00:22 <willikins> No packages have a reverse RDEPEND on net-libs/net6.

amd64 ok based on compile test.
Comment 4 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-11-01 09:26:39 UTC
(In reply to comment #3)
> 00:22 <ago> rdep net6
> 00:22 <willikins> No packages have a reverse RDEPEND on net-libs/net6.
Willikins lied to you :)

10:25 <@xarthisius> !rdep net6
10:25 <+willikins> xarthisius: Reverse RDEPEND for net-libs/net6: 
                   net-libs/obby-0.4.6-r1 net-libs/obby-0.4.7 
                   net-misc/sobby-0.4.7
Comment 5 Agostino Sarubbo gentoo-dev 2011-11-01 09:33:41 UTC
obby compiles fine, sobby is ~arch.

amd64 ok
Comment 6 Ian Delaney (RETIRED) gentoo-dev 2011-11-01 17:40:27 UTC
ditto Ago
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2011-11-02 14:08:19 UTC
Stable for HPPA.
Comment 8 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-11-02 14:46:33 UTC
x86 stable
Comment 9 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-11-02 16:24:58 UTC
+  02 Nov 2011; Kacper Kowalik <xarthisius@gentoo.org> -net6-1.3.9.ebuild,
+  -files/net6-1.3.9-libgnutls.patch:
+  Marked stable on AMD64 based on arch testing by Agostino ago Sarubbo & Ian
+  Delaney in bug #389125. ppc stable, drop old

@security
All arches done
Comment 10 Agostino Sarubbo gentoo-dev 2011-11-02 17:26:36 UTC
> @security
> All arches done

Thanks folks. Added glsa vote request
Comment 11 Tim Sammut (RETIRED) gentoo-dev 2011-11-03 23:23:34 UTC
Thanks, folks. GLSA vote: yes.
Comment 12 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-11-04 07:43:02 UTC
(In reply to comment #11)
> Thanks, folks. GLSA vote: yes.

I'm not sure if GLSA is a good place to do it, but I'd be grateful if you could copy elog message from pkg_postinst[1]. It's not enough to just emerge new version. TIA!

[1]
elog "Please note that because of the use of C++ templates"
elog "Gobby 0.4 has to be recompiled against the new ${PN}"
elog "to pick up the changes."
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2012-03-06 01:08:40 UTC
Vote: NO.
Comment 14 Sean Amoss (RETIRED) gentoo-dev Security 2012-03-06 21:18:03 UTC
Vote: no.

Closing noglsa
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2014-02-13 15:09:57 UTC
CVE-2011-4093 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4093):
  Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might
  allow remote attackers to hijack connections and gain privileges as other
  users by making a large number of connections until the overflow occurs and
  an ID of another user is provided.

CVE-2011-4091 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4091):
  The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14
  does not perform authentication before checking the user name, which allows
  remote attackers to obtain sensitive information such as server-usage
  patterns by a particular user and color preferences.