Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 675214 (CVE-2019-3461)

Summary: <app-admin/tmpreaper-1.6.14: local privilege escalation (CVE-2019-3461)
Product: Gentoo Security Reporter: Georgy Yakovlev <gyakovlev>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: rich0
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.debian.org/security/2019/dsa-4365
Whiteboard: B3 [noglsa cve]
Package list:
app-admin/tmpreaper-1.6.14
Runtime testing required: No

Comment 1 Richard Freeman gentoo-dev 2019-01-12 13:53:59 UTC
I assume the intended target version is 1.16.14, not 1.16.4?
Comment 2 Richard Freeman gentoo-dev 2019-01-12 14:20:19 UTC
(In reply to Richard Freeman from comment #1)
> I assume the intended target version is 1.16.14, not 1.16.4?

And by 1.16.14, I obviously mean 1.6.14...
Comment 3 Larry the Git Cow gentoo-dev 2019-01-12 19:25:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=313e22e9006d9ace56aae404c83cc9cd2015f6d3

commit 313e22e9006d9ace56aae404c83cc9cd2015f6d3
Author:     Richard Freeman <rich0@gentoo.org>
AuthorDate: 2019-01-12 19:25:05 +0000
Commit:     Richard Freeman <rich0@gentoo.org>
CommitDate: 2019-01-12 19:25:05 +0000

    app-admin/tmpreaper: amd64 stable
    
    Bug: https://bugs.gentoo.org/675214
    Signed-off-by: Richard Freeman <rich0@gentoo.org>
    Package-Manager: Portage-2.3.51, Repoman-2.3.11

 app-admin/tmpreaper/tmpreaper-1.6.14.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2019-01-15 22:13:06 UTC
x86 stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2019-01-17 19:59:20 UTC
ppc stable
Comment 6 Larry the Git Cow gentoo-dev 2019-02-04 02:34:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=22ec6789c6965fb4afc02298ec346baf903f672f

commit 22ec6789c6965fb4afc02298ec346baf903f672f
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2019-02-04 02:32:58 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2019-02-04 02:33:59 +0000

    app-admin/tmpreaper: drop vulnerable
    
    Bug: https://bugs.gentoo.org/675214
    Package-Manager: Portage-2.3.59, Repoman-2.3.12
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 app-admin/tmpreaper/Manifest                   |  1 -
 app-admin/tmpreaper/tmpreaper-1.6.13-r1.ebuild | 44 --------------------------
 2 files changed, 45 deletions(-)