Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 552534 (CVE-2015-3248)

Summary: sys-libs/openhpi: world-readable /var/lib/openhpi directory
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: robbat2
Priority: Normal Keywords: PMASKED
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=1233520
Whiteboard: ~3 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2015-06-19 08:11:20 UTC
From ${URL} :

openhpi ships with the /var/lib/openhpi/ directory set world readable and 
writeable. If this directory is used for storing the OPENHPI_UID_MAP or other
openhpi data for exam,p[le an attacker would be able to view, modify and delete 
it. Even without such usage an attacker could use it to fill up the storage
hosting the /var/lib/ directory if quotas are not properly set.

NOTE:
On Gentoo this is only world-readable instead of world-writable.


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-04-04 08:40:59 UTC
This is fixed upstream in >=3.6.0:

http://openhpi.org/Changelogs/3.6.0

@maintainer, please bump the package and cleanup the vulnerable versions.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-07-03 06:45:23 UTC
@maintainer, ping.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-11-20 12:24:55 UTC
@maintainer, any intention on bumping this?
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-11-25 15:43:39 UTC
@treecleaners, maintainer has expressed his intention of dropping the package.  Preferably clean the package or assign to maintainer-needed.
Comment 5 Pacho Ramos gentoo-dev 2016-12-31 13:51:15 UTC
dropped
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2016-12-31 14:42:50 UTC
Unstable package dropped.