Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 728770 (CVE-2020-14019) - <dev-python/rtslib-fb-2.1.73: Weak permissions used on /etc/target/saveconfig.json (CVE-2020-14019)
Summary: <dev-python/rtslib-fb-2.1.73: Weak permissions used on /etc/target/saveconfig...
Status: RESOLVED FIXED
Alias: CVE-2020-14019
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/open-iscsi/rtslib-...
Whiteboard: B4 [noglsa cleanup]
Keywords:
Depends on:
Blocks: python3.8-stable, python38-stable-needed
  Show dependency tree
 
Reported: 2020-06-19 13:40 UTC by Sam James
Modified: 2020-08-29 22:22 UTC (History)
3 users (show)

See Also:
Package list:
dev-python/rtslib-fb-2.1.73
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-19 13:40:58 UTC
Description:
"Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved."
Comment 1 Diogo Pereira 2020-08-01 22:11:36 UTC
Bump to 2.1.73 here: https://github.com/gentoo/gentoo/pull/16516
Comment 2 Larry the Git Cow gentoo-dev 2020-08-15 01:18:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c3e3e50d15b7c4453e25338ea5f0ad216d95c964

commit c3e3e50d15b7c4453e25338ea5f0ad216d95c964
Author:     Diogo Pereira <sir.suriv@gmail.com>
AuthorDate: 2020-06-30 22:56:30 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2020-08-15 01:18:17 +0000

    dev-python/rtslib-fb: version bump to 2.1.73
    
    Bug: https://bugs.gentoo.org/728770
    Package-Manager: Portage-2.3.103, Repoman-2.3.23
    Signed-off-by: Diogo Pereira <sir.suriv@gmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/16516
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-python/rtslib-fb/Manifest                |  1 +
 dev-python/rtslib-fb/rtslib-fb-2.1.73.ebuild | 24 ++++++++++++++++++++++++
 2 files changed, 25 insertions(+)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-19 13:43:50 UTC
Tell us when ready to stable. Will look at PR soon.
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-25 00:04:57 UTC
(In reply to Sam James from comment #3)
> Tell us when ready to stable. Will look at PR soon.

I guess we'll go ahead.
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-25 01:41:07 UTC
x86 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-25 12:34:01 UTC
amd64 done

all arches done
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-25 12:41:43 UTC
Please cleanup.
Comment 8 Larry the Git Cow gentoo-dev 2020-08-29 22:21:49 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7a62a6b9db1ce96cf458e0ac5a81a0de9a067151

commit 7a62a6b9db1ce96cf458e0ac5a81a0de9a067151
Author:     Aaron Bauman <bman@gentoo.org>
AuthorDate: 2020-08-29 22:21:21 +0000
Commit:     Aaron Bauman <bman@gentoo.org>
CommitDate: 2020-08-29 22:21:44 +0000

    dev-python/rtslib-fb: drop vulnerable
    
    Bug: https://bugs.gentoo.org/728770
    
    Signed-off-by: Aaron Bauman <bman@gentoo.org>

 dev-python/rtslib-fb/Manifest                |  1 -
 dev-python/rtslib-fb/rtslib-fb-2.1.69.ebuild | 24 ------------------------
 2 files changed, 25 deletions(-)