Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 471176 (CVE-2013-2069) - app-misc/livecd-tools : improper handling of passwords
Summary: app-misc/livecd-tools : improper handling of passwords
Status: RESOLVED INVALID
Alias: CVE-2013-2069
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-24 18:00 UTC by Agostino Sarubbo
Modified: 2013-05-25 01:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-24 18:00:00 UTC
From ${URL} :

The livecd-tools package provides support for reading and executing
Kickstart files in order to create a system image. It was discovered
that livecd-tools gave the root user an empty password rather than
leaving the password locked in situations where no 'rootpw' directive
was used or when the 'rootpw --lock' directive was used within the
Kickstart file, which could allow local users to gain access to the
root account. (CVE-2013-2069)

Please note that livecd-tools is also used by appliance-tools to create
images used for virtual machines, USB based systems, and so on.
Additionally, the Python script components of livecd-tools have been
broken out into a separate package named python-imgcreate on some
distributions.


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 William Hubbs gentoo-dev 2013-05-24 22:11:51 UTC
We do not use the same livecd-tools RH uses, so I don't think this applies to us.
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2013-05-24 22:37:50 UTC
hooray for auto-filing bugs
Comment 3 SpanKY gentoo-dev 2013-05-25 01:12:47 UTC
sounds like a good use case for the CPE fields in metadata.xml