Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 189249 - app-misc/tomboy < 0.8.1-r1 Insecure LD_LIBRARY_PATH Privilege Escalation (CVE-2005-4790)
Summary: app-misc/tomboy < 0.8.1-r1 Insecure LD_LIBRARY_PATH Privilege Escalation (CVE...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26480/
Whiteboard: B1 [glsa]
Keywords:
: 188806 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-08-17 16:50 UTC by Matt Fleming (RETIRED)
Modified: 2007-11-08 20:10 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
tomboy-trunk-insecure-ldpath.patch (tomboy-trunk-insecure-ldpath.patch,1.41 KB, patch)
2007-10-15 23:32 UTC, Robert Buchholz (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Fleming (RETIRED) gentoo-dev 2007-08-17 16:50:44 UTC
Jab Oravec has reported a security issue in Tomboy, which can be exploited by malicious, local users to gain escalated privileges.

The security issue is caused due to the "/usr/bin/tomboy" script incorrectly setting the environment variable LD_LIBRARY_PATH. This can be exploited to gain escalated privileges by e.g. tricking a user into running Tomboy in a directory containing a malicious library.
Comment 1 Matt Fleming (RETIRED) gentoo-dev 2007-08-17 16:52:35 UTC
CC'ing maintainers and setting whiteboard status.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-23 12:15:49 UTC
*** Bug 188806 has been marked as a duplicate of this bug. ***
Comment 3 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-27 22:05:50 UTC
0.8.0 has been released couple days ago, anyone knows if includes a fix for this? I don't see anything in the changelog...
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-10-09 23:08:58 UTC
Upstream bug filed: http://bugzilla.gnome.org/show_bug.cgi?id=485224
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2007-10-15 23:32:38 UTC
Created attachment 133582 [details, diff]
tomboy-trunk-insecure-ldpath.patch

Should fix this issue.
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2007-10-24 22:24:18 UTC
As upstream is unresponsive could you please include the patch without the change from sh -> bash in the first line (I talked to uberlord about it, the syntax is not bash specific as I first thought)?
Comment 7 Robert Buchholz (RETIRED) gentoo-dev 2007-11-04 01:32:29 UTC
[02:30] <compnerd> rbu: tomboy-0.8.1-r1 commited
[02:30] <rbu> compnerd: thanks

Arches, please test and mark stable app-misc/tomboy-0.8.1-r1.
Target keywords : "amd64 ppc x86"
Comment 8 Dawid Węgliński (RETIRED) gentoo-dev 2007-11-04 10:17:59 UTC
Stable on x86
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2007-11-05 18:01:09 UTC
ppc stable
Comment 10 Chris Gianelloni (RETIRED) gentoo-dev 2007-11-06 00:53:33 UTC
err... amd64 done... sorry
Comment 11 Robert Buchholz (RETIRED) gentoo-dev 2007-11-06 01:11:43 UTC
GLSA request filed.
Comment 12 Chris Gianelloni (RETIRED) gentoo-dev 2007-11-06 19:21:35 UTC
I've updated this in the snapshot, so I'm removing release.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-08 20:10:37 UTC
GLSA 200711-12