Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 193132 - media-sound/gnump3d user/passwords can be bypassed (CVE-2007-6130)
Summary: media-sound/gnump3d user/passwords can be bypassed (CVE-2007-6130)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-20 02:25 UTC by James
Modified: 2008-03-06 09:43 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description James 2007-09-20 02:25:41 UTC
gnump3d offers a security setting involving a username:password combination that can be easily bypassed.

Reproducible: Always

Steps to Reproduce:
1. Connect to gnump3d webserver with the password security option enabled and a file called .password in the main directory your music files are saved in.
2. When it asks for a username and password, click cancel. The server will tell you that you've been denied.
3. Click 'search', and type in a search term that will give results based upon your music library.

Actual Results:  
The server allows you to download and/or stream music to you based upon your preferences or server settings, bypassing the username/password security setting.

Expected Results:  
You shouldn't be able to browse or download music without presenting the proper credentials.  It should deny anyone who does not give a proper username and password combination

Works with all browsers.
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-20 12:29:52 UTC
Thanks for your report James. Did you discovered this issue? Have you contacted upstream about it?
Comment 2 James 2007-09-21 01:17:48 UTC
(In reply to comment #1)
> Thanks for your report James. Did you discovered this issue? Have you contacted
> upstream about it?
> 

I did discover it. After my logfile quadrupled overnight, I noticed someone (resolved to a Korean ip) downloaded most of my library overnight. Noticing that they didn't use a username/password, I simply clicked 'cancel' when firefox asked me for them, and I had full access. :x

As for upstream, I have emailed steve (at) steve.org.uk, the contact email for the author of gnump3d, but as of yet, I have not received a response.
Comment 3 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-21 07:28:31 UTC
(In reply to comment #2)
> (In reply to comment #1)
> > Thanks for your report James. Did you discovered this issue? Have you contacted
> > upstream about it?
> > 
> 
> I did discover it. After my logfile quadrupled overnight, I noticed someone
> (resolved to a Korean ip) downloaded most of my library overnight. Noticing
> that they didn't use a username/password, I simply clicked 'cancel' when
> firefox asked me for them, and I had full access. :x
> 
> As for upstream, I have emailed steve (at) steve.org.uk, the contact email for
> the author of gnump3d, but as of yet, I have not received a response.
> 

OK, so we'll wait a few days so that they can patch this.
Just a note: please don't modify the bug fields once they've been set or corrected by a developer ;)
Comment 4 James 2007-09-22 04:01:34 UTC
(In reply to comment #3)
> (In reply to comment #2)
> > (In reply to comment #1)
> > > Thanks for your report James. Did you discovered this issue? Have you contacted
> > > upstream about it?
> > > 
> > 
> > I did discover it. After my logfile quadrupled overnight, I noticed someone
> > (resolved to a Korean ip) downloaded most of my library overnight. Noticing
> > that they didn't use a username/password, I simply clicked 'cancel' when
> > firefox asked me for them, and I had full access. :x
> > 
> > As for upstream, I have emailed steve (at) steve.org.uk, the contact email for
> > the author of gnump3d, but as of yet, I have not received a response.
> > 
> 
> OK, so we'll wait a few days so that they can patch this.
> Just a note: please don't modify the bug fields once they've been set or
> corrected by a developer ;)
> 

I'm not sure how I messed that up. Sorry :x
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-10-08 13:49:35 UTC
James, any news from upstream?
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2007-11-02 03:38:02 UTC
From upstream ChangeLog:

  3.0 [ 17th October 2007]
   - Removed several perl warnings.
   - Removed password protection as being broken beyond repair.

No security is better than bad security.
Sound, can you provide an updated ebuild?
Comment 7 Robert Buchholz (RETIRED) gentoo-dev 2007-11-02 03:38:29 UTC
From upstream ChangeLog:

  3.0 [ 17th October 2007]
   - Removed several perl warnings.
   - Removed password protection as being broken beyond repair.

No security is better than bad security.
Sound, can you provide an updated ebuild?
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-14 22:19:15 UTC
(In reply to comment #7)
> From upstream ChangeLog:
> 
>   3.0 [ 17th October 2007]
>    - Removed several perl warnings.
>    - Removed password protection as being broken beyond repair.
> 
> No security is better than bad security.
> Sound, can you provide an updated ebuild?
> 

*ping*
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2007-11-20 00:48:29 UTC
Sound, please bump.
Comment 10 Samuli Suominen (RETIRED) gentoo-dev 2007-11-20 09:23:43 UTC
Sorry.. I'll _try_ to get it today. So much to do, so little time ;)
Comment 11 Alexis Ballier gentoo-dev 2007-11-25 00:00:49 UTC
bumped, sorry for the delay
Comment 12 Robert Buchholz (RETIRED) gentoo-dev 2007-11-25 12:20:59 UTC
Thanks.

Arches, please test and mark stable media-sound/gnump3d-3.0.
Target keywords : "alpha amd64 ppc64 sparc x86"
Comment 13 Markus Rothe (RETIRED) gentoo-dev 2007-11-25 13:57:42 UTC
ppc64 stable
Comment 14 Christian Faulhammer (RETIRED) gentoo-dev 2007-11-25 14:54:16 UTC
x86 stable
Comment 15 Raúl Porcel (RETIRED) gentoo-dev 2007-11-28 16:57:05 UTC
alpha/sparc stable
Comment 16 Steve Dibb (RETIRED) gentoo-dev 2007-11-30 21:32:36 UTC
amd64 stable
Comment 17 Robert Buchholz (RETIRED) gentoo-dev 2007-12-02 12:25:01 UTC
This issue was only introduced in the 2.9final release (bug 182814) which hit the tree 05 Aug 2007 and never went stable.

Closing [noglsa] therefore.
Comment 18 Peter Volkov (RETIRED) gentoo-dev 2008-03-06 09:43:00 UTC
Does not affect current (2008.0) release. Removing release.