Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 431420 - <sys-fs/quota-3.17: Bypassing of TCP Wrappers rules in hosts.deny (CVE-2012-3417)
Summary: <sys-fs/quota-3.17: Bypassing of TCP Wrappers rules in hosts.deny (CVE-2012-3...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-08-14 18:29 UTC by GLSAMaker/CVETool Bot
Modified: 2012-08-16 04:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-08-14 18:29:38 UTC
CVE-2012-3417 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3417):
  The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka
  quota) before 3.17 invokes the hosts_ctl function the first time without a
  host name, which might allow remote attackers to bypass TCP Wrappers rules
  in hosts.deny.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2012-08-14 18:31:41 UTC
This is already stable and ready for voting.

I vote NO.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-08-16 04:52:15 UTC
GLSA Vote: no too. closing noglsa.