Summary: | sys-cluster/cluster-glue: root privilege escalation via "chown -R" in pkg_postinst | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Michael Orlitzky <mjo> |
Component: | Auditing | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | normal | CC: | alexxy, bircoph, cluster, jer, jsbronder, kfm, mschiff, pchrist, prometheanfire, treecleaner, ultrabug |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B1 [ebuild] | ||
Package list: | Runtime testing required: | --- | |
Deadline: | 2020-12-07 |
Description
Michael Orlitzky
![]() Note that the ebuilds also set /dev/null as login shell. pkg_setup() { enewgroup haclient enewuser hacluster -1 /dev/null /var/lib/heartbeat haclient } I expect no security implications there but that probably ought to be fixed in this same effort: enewuser hacluster -1 -1 /var/lib/heartbeat haclient Unrestricting and reassigning to security@ per bug #705894 unrestricting per bug 705894 |