|Summary:||app-misc/tomboy < 0.8.1-r1 Insecure LD_LIBRARY_PATH Privilege Escalation (CVE-2005-4790)|
|Product:||Gentoo Security||Reporter:||Matt Fleming (RETIRED) <mjf>|
|Component:||Vulnerabilities||Assignee:||Gentoo Security <security>|
|Severity:||major||CC:||compnerd, jan.oravec, latexer|
|Package list:||Runtime testing required:||---|
Description Matt Fleming (RETIRED) 2007-08-17 16:50:44 UTC
Jab Oravec has reported a security issue in Tomboy, which can be exploited by malicious, local users to gain escalated privileges. The security issue is caused due to the "/usr/bin/tomboy" script incorrectly setting the environment variable LD_LIBRARY_PATH. This can be exploited to gain escalated privileges by e.g. tricking a user into running Tomboy in a directory containing a malicious library.
Comment 1 Matt Fleming (RETIRED) 2007-08-17 16:52:35 UTC
CC'ing maintainers and setting whiteboard status.
Comment 2 Pierre-Yves Rofes (RETIRED) 2007-08-23 12:15:49 UTC
*** Bug 188806 has been marked as a duplicate of this bug. ***
Comment 3 Pierre-Yves Rofes (RETIRED) 2007-09-27 22:05:50 UTC
0.8.0 has been released couple days ago, anyone knows if includes a fix for this? I don't see anything in the changelog...
Comment 4 Robert Buchholz (RETIRED) 2007-10-09 23:08:58 UTC
Upstream bug filed: http://bugzilla.gnome.org/show_bug.cgi?id=485224
Comment 5 Robert Buchholz (RETIRED) 2007-10-15 23:32:38 UTC
Created attachment 133582 [details, diff] tomboy-trunk-insecure-ldpath.patch Should fix this issue.
Comment 6 Robert Buchholz (RETIRED) 2007-10-24 22:24:18 UTC
As upstream is unresponsive could you please include the patch without the change from sh -> bash in the first line (I talked to uberlord about it, the syntax is not bash specific as I first thought)?
Comment 7 Robert Buchholz (RETIRED) 2007-11-04 01:32:29 UTC
[02:30] <compnerd> rbu: tomboy-0.8.1-r1 commited [02:30] <rbu> compnerd: thanks Arches, please test and mark stable app-misc/tomboy-0.8.1-r1. Target keywords : "amd64 ppc x86"
Comment 8 Dawid Węgliński (RETIRED) 2007-11-04 10:17:59 UTC
Stable on x86
Comment 9 Tobias Scherbaum (RETIRED) 2007-11-05 18:01:09 UTC
Comment 10 Chris Gianelloni (RETIRED) 2007-11-06 00:53:33 UTC
err... amd64 done... sorry
Comment 11 Robert Buchholz (RETIRED) 2007-11-06 01:11:43 UTC
GLSA request filed.
Comment 12 Chris Gianelloni (RETIRED) 2007-11-06 19:21:35 UTC
I've updated this in the snapshot, so I'm removing release.
Comment 13 Pierre-Yves Rofes (RETIRED) 2007-11-08 20:10:37 UTC