Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 131866 - sys-apps/resmgr possible unauthorised access
Summary: sys-apps/resmgr possible unauthorised access
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo TreeCleaner Project
URL: http://www.debian.org/security/2006/d...
Whiteboard: Pending removal 09 Jun 2007
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2006-04-30 23:30 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-06-26 17:44 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-04-30 23:30:19 UTC
A problem has been discovered in resmgr, a resource manager library daemon and PAM module, that allows local users to bypass access control rules and open any USB device when access to one device was granted.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2006-05-02 09:31:50 UTC
Ccing maintainer for advice : new version / patch ?
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2006-05-09 10:12:42 UTC
Pylon, any news ?
Comment 3 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-27 04:28:01 UTC
sbriesen, please comment if this can be removed or masked
Comment 4 Stefan Briesenick (RETIRED) gentoo-dev 2006-05-27 11:42:02 UTC
please mask it in the first place. I will investigate it further. Perhaps there is a patch available.

But with latest 2.6 kernels, resmgr is not so important anymore. So if there is no fix, I would remove it from portage.
Comment 5 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-27 11:56:29 UTC
Thank you, I masked it. Keeping bug open as enh. until patch/removal

actually was never stable, so we dont need to care about tempglsa
Comment 6 Stefan Briesenick (RETIRED) gentoo-dev 2006-09-08 10:58:50 UTC
I guess we can close this bug.

reopen for final removal.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-09 09:20:02 UTC
Stefan we (Security) normally keep bugs open until it is removed or unmasked again (with Severity enhancement).
Comment 8 Stefan Briesenick (RETIRED) gentoo-dev 2006-09-09 11:55:31 UTC
ups. sorry. my fault.
Comment 9 Jakub Moc (RETIRED) gentoo-dev 2006-12-16 20:17:12 UTC
# Stefan Cornelius <dercorny@gentoo.org> (27 May 2006)
# Masked because of security bug #131866
sys-apps/resmgr

Hasn't seen a release since 2003. Someone please remove this cruft, thanks. 
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2007-04-05 09:03:40 UTC
Treecleaners turn.

Please vote.
Comment 11 Ryan Hill (RETIRED) gentoo-dev 2007-04-06 00:37:32 UTC
++
Comment 12 Christian Heim (RETIRED) gentoo-dev 2007-04-09 17:46:12 UTC
Yeah, I think this can be removed if the maintainers don't wish to keep it. Debian has a patch for it (at least from the looks of the dsa), but upstream is still at resmgr-1.0.

So my vote is also, yes.
Comment 13 Raúl Porcel (RETIRED) gentoo-dev 2007-06-26 17:44:12 UTC
Removed, forgot about this one.