Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 471176 (CVE-2013-2069)

Summary: app-misc/livecd-tools : improper handling of passwords
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: normal CC: livecd
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=964299
Whiteboard:
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2013-05-24 18:00:00 UTC
From ${URL} :

The livecd-tools package provides support for reading and executing
Kickstart files in order to create a system image. It was discovered
that livecd-tools gave the root user an empty password rather than
leaving the password locked in situations where no 'rootpw' directive
was used or when the 'rootpw --lock' directive was used within the
Kickstart file, which could allow local users to gain access to the
root account. (CVE-2013-2069)

Please note that livecd-tools is also used by appliance-tools to create
images used for virtual machines, USB based systems, and so on.
Additionally, the Python script components of livecd-tools have been
broken out into a separate package named python-imgcreate on some
distributions.


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 William Hubbs gentoo-dev 2013-05-24 22:11:51 UTC
We do not use the same livecd-tools RH uses, so I don't think this applies to us.
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2013-05-24 22:37:50 UTC
hooray for auto-filing bugs
Comment 3 SpanKY gentoo-dev 2013-05-25 01:12:47 UTC
sounds like a good use case for the CPE fields in metadata.xml