Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 459274 - <www-servers/monkeyd-1.6.9-r1: world-redable logdir
Summary: <www-servers/monkeyd-1.6.9-r1: world-redable logdir
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 585064
Blocks:
  Show dependency tree
 
Reported: 2013-02-26 09:45 UTC by Agostino Sarubbo
Modified: 2016-10-22 13:10 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-02-26 09:45:52 UTC
From ${URL} :

Monkeyd, a small, fast, and scalable web server, produces, at least on gentoo 
a world-readable log.

# ls /var/log/monkeyd/master.log -la
-rw-r--r-- 1 root root 0 Feb 24 19:56 /var/log/monkeyd/master.log

Upstream site: http://www.monkey-project.com/
Comment 1 Anthony Basile gentoo-dev 2015-03-03 11:37:13 UTC
This should be fixed.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-07-01 01:40:11 UTC
# Aaron Bauman <bman@gentoo.org> (1 Jul 2016)
# Unpatched security vulnerabilities and dead upstream
# per bugs #459274 and #473770  Removal in 30 days
www-servers/monkeyd
Comment 3 Anthony Basile gentoo-dev 2016-07-01 02:35:40 UTC
(In reply to Aaron Bauman from comment #2)
> # Aaron Bauman <bman@gentoo.org> (1 Jul 2016)
> # Unpatched security vulnerabilities and dead upstream
> # per bugs #459274 and #473770  Removal in 30 days
> www-servers/monkeyd

What!  No.  This has been fixed.  Do not tell me your p.masked this package!
Comment 4 Anthony Basile gentoo-dev 2016-07-01 02:43:19 UTC
(In reply to Anthony Basile from comment #3)
> (In reply to Aaron Bauman from comment #2)
> > # Aaron Bauman <bman@gentoo.org> (1 Jul 2016)
> > # Unpatched security vulnerabilities and dead upstream
> > # per bugs #459274 and #473770  Removal in 30 days
> > www-servers/monkeyd
> 
> What!  No.  This has been fixed.  Do not tell me your p.masked this package!

I reverted this.  (In reply to Anthony Basile from comment #3)
> (In reply to Aaron Bauman from comment #2)
> > # Aaron Bauman <bman@gentoo.org> (1 Jul 2016)
> > # Unpatched security vulnerabilities and dead upstream
> > # per bugs #459274 and #473770  Removal in 30 days
> > www-servers/monkeyd
> 
> What!  No.  This has been fixed.  Do not tell me your p.masked this package!

I have reverted this masking.  You should not go around masking peoples packages without their acknowledgement expecially since this has been fixed.
Comment 5 Alex Legler (RETIRED) archtester gentoo-dev Security 2016-07-01 06:51:17 UTC
(In reply to Anthony Basile from comment #4)
> I have reverted this masking.  You should not go around masking peoples
> packages without their acknowledgement expecially since this has been fixed.

In what version?

We'll close our bugs as per to our usual process, thanks.
Comment 6 Anthony Basile gentoo-dev 2016-07-01 09:52:41 UTC
(In reply to Alex Legler from comment #5)
> (In reply to Anthony Basile from comment #4)
> > I have reverted this masking.  You should not go around masking peoples
> > packages without their acknowledgement expecially since this has been fixed.
> 
> In what version?
> 
> We'll close our bugs as per to our usual process, thanks.

Since when is a world readable log a security bug which merits p.mask-ing and removal?
Comment 7 Anthony Basile gentoo-dev 2016-07-01 11:48:35 UTC
(In reply to Anthony Basile from comment #6)
> (In reply to Alex Legler from comment #5)
> > (In reply to Anthony Basile from comment #4)
> > > I have reverted this masking.  You should not go around masking peoples
> > > packages without their acknowledgement expecially since this has been fixed.
> > 
> > In what version?
> > 
> > We'll close our bugs as per to our usual process, thanks.
> 
> Since when is a world readable log a security bug which merits p.mask-ing
> and removal?

actually the problem isn't master.log which logs nothing you can't get with ps and netstat.  the bigger problem is access.log and error.log in the default configuration.  i can tighten that up, but this is not a security bug.
Comment 8 Anthony Basile gentoo-dev 2016-07-01 17:20:24 UTC
(In reply to Anthony Basile from comment #7)
> (In reply to Anthony Basile from comment #6)
> > (In reply to Alex Legler from comment #5)
> > > (In reply to Anthony Basile from comment #4)
> > > > I have reverted this masking.  You should not go around masking peoples
> > > > packages without their acknowledgement expecially since this has been fixed.
> > > 
> > > In what version?
> > > 
> > > We'll close our bugs as per to our usual process, thanks.
> > 
> > Since when is a world readable log a security bug which merits p.mask-ing
> > and removal?
> 
> actually the problem isn't master.log which logs nothing you can't get with
> ps and netstat.  the bigger problem is access.log and error.log in the
> default configuration.  i can tighten that up, but this is not a security
> bug.

version 1.6.9-r1 and above restrict access to access.lgo and error.log.
Comment 9 Anthony Basile gentoo-dev 2016-07-01 17:55:13 UTC
(In reply to Anthony Basile from comment #8)
> 
> version 1.6.9-r1 and above restrict access to access.lgo and error.log.

to be clear 1.6.9-r1 and above fix the world readable logdir.
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2016-07-04 12:16:03 UTC
(In reply to Anthony Basile from comment #9)
> (In reply to Anthony Basile from comment #8)
> > 
> > version 1.6.9-r1 and above restrict access to access.lgo and error.log.
> 
> to be clear 1.6.9-r1 and above fix the world readable logdir.

may we call for stabilization of www-servers/monkeyd-1.6.9-r1?  This will also fix bug 473770 giving your testing.
Comment 11 Anthony Basile gentoo-dev 2016-07-04 12:33:28 UTC
(In reply to Aaron Bauman from comment #10)
> (In reply to Anthony Basile from comment #9)
> > (In reply to Anthony Basile from comment #8)
> > > 
> > > version 1.6.9-r1 and above restrict access to access.lgo and error.log.
> > 
> > to be clear 1.6.9-r1 and above fix the world readable logdir.
> 
> may we call for stabilization of www-servers/monkeyd-1.6.9-r1?  This will
> also fix bug 473770 giving your testing.

wait a month.

bug #473770 was never verified for any versions.  it should be closed invalid.
Comment 12 Aaron Bauman (RETIRED) gentoo-dev 2016-07-04 12:48:02 UTC
(In reply to Anthony Basile from comment #11)
> (In reply to Aaron Bauman from comment #10)
> > (In reply to Anthony Basile from comment #9)
> > > (In reply to Anthony Basile from comment #8)
> > > > 
> > > > version 1.6.9-r1 and above restrict access to access.lgo and error.log.
> > > 
> > > to be clear 1.6.9-r1 and above fix the world readable logdir.
> > 
> > may we call for stabilization of www-servers/monkeyd-1.6.9-r1?  This will
> > also fix bug 473770 giving your testing.
> 
> wait a month.
> 
> bug #473770 was never verified for any versions.  it should be closed
> invalid.

So the code bases are different?(In reply to Anthony Basile from comment #11)
> (In reply to Aaron Bauman from comment #10)
> > (In reply to Anthony Basile from comment #9)
> > > (In reply to Anthony Basile from comment #8)
> > > > 
> > > > version 1.6.9-r1 and above restrict access to access.lgo and error.log.
> > > 
> > > to be clear 1.6.9-r1 and above fix the world readable logdir.
> > 
> > may we call for stabilization of www-servers/monkeyd-1.6.9-r1?  This will
> > also fix bug 473770 giving your testing.
> 
> wait a month.
> 
> bug #473770 was never verified for any versions.  it should be closed
> invalid.

Tomorrow will mark 1 month of the usual 30 day stabilization period, still another month?
Comment 13 Anthony Basile gentoo-dev 2016-07-04 13:03:11 UTC
(In reply to Aaron Bauman from comment #12)
> (In reply to Anthony Basile from comment #11)
> > 
> > 
> > bug #473770 was never verified for any versions.  it should be closed
> > invalid.
> 
> So the code bases are different?(In reply to Anthony Basile from comment #11)

Not enough information was given by the original reporter.  After filing the bug he disappeared.
Comment 14 Aaron Bauman (RETIRED) gentoo-dev 2016-10-14 09:21:02 UTC
@arches, please stabilize the following:

=www-servers/monkeyd-1.6.9-r1
Comment 15 Anthony Basile gentoo-dev 2016-10-22 12:53:00 UTC
(In reply to Aaron Bauman from comment #14)
> @arches, please stabilize the following:
> 
> =www-servers/monkeyd-1.6.9-r1

This is bug #585064
Comment 16 Aaron Bauman (RETIRED) gentoo-dev 2016-10-22 12:56:04 UTC
(In reply to Anthony Basile from comment #15)
> (In reply to Aaron Bauman from comment #14)
> > @arches, please stabilize the following:
> > 
> > =www-servers/monkeyd-1.6.9-r1
> 
> This is bug #585064

You can call for stabilization in the security bug, which I mentioned on IRC as well.  Makes tracking that much easier.
Comment 17 Anthony Basile gentoo-dev 2016-10-22 13:08:57 UTC
(In reply to Anthony Basile from comment #15)
> (In reply to Aaron Bauman from comment #14)
> > @arches, please stabilize the following:
> > 
> > =www-servers/monkeyd-1.6.9-r1
> 
> This is bug #585064

I've finished the stabilization on all arches and removed the older version.
Comment 18 Aaron Bauman (RETIRED) gentoo-dev 2016-10-22 13:10:49 UTC
(In reply to Anthony Basile from comment #17)
> (In reply to Anthony Basile from comment #15)
> > (In reply to Aaron Bauman from comment #14)
> > > @arches, please stabilize the following:
> > > 
> > > =www-servers/monkeyd-1.6.9-r1
> > 
> > This is bug #585064
> 
> I've finished the stabilization on all arches and removed the older version.

Thanks, Anthony!

GLSA Vote: No