Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 463338 (CVE-2013-2561) - sys-fabric/ibutils: improper use of files in /tmp (CVE-2013-2561)
Summary: sys-fabric/ibutils: improper use of files in /tmp (CVE-2013-2561)
Status: RESOLVED FIXED
Alias: CVE-2013-2561
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Deadline: 2019-12-31
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~3 [noglsa cve]
Keywords: PATCH, PMASKED
Depends on:
Blocks:
 
Reported: 2013-03-26 10:10 UTC by Agostino Sarubbo
Modified: 2020-04-26 04:08 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-03-26 10:10:35 UTC
From ${URL} :

It was reported on full-disclosure that ibutils suffers from improper
use of files /tmp that could allow a user to clobber files as the user
running ibutils (probably usually root).

References:

http://seclists.org/fulldisclosure/2013/Mar/87
https://bugzilla.redhat.com/show_bug.cgi?id=927430
Comment 1 Alexey Shvetsov archtester gentoo-dev 2013-03-26 17:22:16 UTC
I will update it ASAP to version from ofed-3.5.0
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-12-12 17:39:25 UTC
CVE-2013-2561 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2561):
  OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files
  via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3)
  ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6)
  ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl,
  or (10) ibdiagnet.sm in /tmp/.
Comment 3 Alexey Shvetsov archtester gentoo-dev 2016-06-30 07:41:17 UTC
Old versions removed from tree
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-06-30 08:31:16 UTC
(In reply to Alexey Shvetsov from comment #3)
> Old versions removed from tree

Thanks.  Still trying to track where the vulnerability was fixed.  If I cannot find anything, I will try to replicate the symlink attack when I get a bit more time.
Comment 5 Alexey Shvetsov archtester gentoo-dev 2016-06-30 08:42:25 UTC
You may wanna wait a little bit. I'll add new versions that was released recently
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2016-06-30 09:24:39 UTC
(In reply to Alexey Shvetsov from comment #5)
> You may wanna wait a little bit. I'll add new versions that was released
> recently

Well that is the issue.  No information shows where the vulnerability was patched.
Comment 7 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-07-20 14:09:57 UTC
UPDATE:

I've tried to replicate the same issue on ibutils-1.5.7-0.2.gbd7e502.tar.gz

the result:

-E- The following tile is write protected: /tmp/ibdiagnet.log
    Error message: "couldn't open "/tmp/ibdiagnet.log": permission denied"
    Exiting

I've tested it on an arch vm which has the latest ibutils version,


@Maintainers: could you please confirm if there is going to be a version bump since the package is masked right now?
Comment 8 Thomas Deutschmann (RETIRED) gentoo-dev 2018-02-24 16:34:49 UTC
The current package in Gentoo repository is still vulnerable.

@ Maintainer(s): Please apply the following patch from Red Hat (https://salsa.debian.org/hpc-team/ibutils/blob/master/debian/patches/do_not_use_tmp.patch) which changes ibutils default tmp path to /var/cache/ibutils which can be locked down.
Comment 9 Larry the Git Cow gentoo-dev 2019-12-01 21:00:17 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=03325ebfa6d282818310103f8ce387bc5f2965c1

commit 03325ebfa6d282818310103f8ce387bc5f2965c1
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2019-12-01 20:26:22 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2019-12-01 20:59:54 +0000

    package.mask: Last rite sys-fabric/ibutils
    
    Bug: https://bugs.gentoo.org/463338
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 profiles/package.mask | 5 +++++
 1 file changed, 5 insertions(+)
Comment 10 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2020-01-07 10:51:21 UTC
The package is now gone.