Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 65544 - net-analyzer/fprobe: unspecified security fix
Summary: net-analyzer/fprobe: unspecified security fix
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://sourceforge.net/project/showno...
Whiteboard: C? [glsa?] lewk
Keywords:
Depends on:
Blocks:
 
Reported: 2004-09-27 08:18 UTC by Luke Macken (RETIRED)
Modified: 2011-10-30 22:38 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Luke Macken (RETIRED) gentoo-dev 2004-09-27 08:18:28 UTC
In the ChangeLog for version 1.0.6, it says:

	- security fix for "change user" feature

That is all of the information that we have about this vulnerability.

See also http://secunia.com/advisories/12648/
Comment 1 Luke Macken (RETIRED) gentoo-dev 2004-09-27 08:19:50 UTC
squinky86, please bump to 1.0.6.
Comment 2 Jon Hood (RETIRED) gentoo-dev 2004-09-27 11:56:51 UTC
Stable x86, vulnerable versions removed, ready for GLSA. Thanks lewk :)
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2004-09-27 13:49:40 UTC
Hmmm... short of analyzing the changes in the new version and determine what has been fixed, I would say we can't issue a GLSA for that.
Comment 4 Dan Margolis (RETIRED) gentoo-dev 2004-09-27 14:12:37 UTC
I'd drop a line to the maintainer (sla@users.sourceforge.net) and just ask him for clarification. 
Comment 5 Luke Macken (RETIRED) gentoo-dev 2004-09-27 15:28:41 UTC
Dropped a line upstream to find out some more details of this "security fix" so we can decide if we want to issue a GLSA for this or not.
Comment 6 Luke Macken (RETIRED) gentoo-dev 2004-09-28 05:46:07 UTC
Upstream responded with these details:

The idea of "change user" security fix consist in changing EUID in each thread 
independently of main thread. This is workaround for clone(2)-based threads 
(eg. Linux 2.4.x), where thread actually a lightweight process, so changing 
EUID in main thread doesn't influence on child threads. Therefore in previous 
version potential-vulnerable capture thread always works with EUID 0, without 
regard to '-u' parameter.
Comment 7 Luke Macken (RETIRED) gentoo-dev 2004-09-28 06:00:05 UTC
Security, vote on GLSA?
Comment 8 Luke Macken (RETIRED) gentoo-dev 2004-09-28 06:15:23 UTC
Closing without GLSA