Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 372913 (CVE-2011-2471) - <dev-util/oprofile-0.9.6-r1: multiple vulnerabilities (CVE-2011-{2471,2472,2473})
Summary: <dev-util/oprofile-0.9.6-r1: multiple vulnerabilities (CVE-2011-{2471,2472,24...
Status: RESOLVED DUPLICATE of bug 366699
Alias: CVE-2011-2471
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-06-24 21:31 UTC by GLSAMaker/CVETool Bot
Modified: 2011-07-03 16:16 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 21:31:46 UTC
CVE-2011-2473 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2473):
  The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier
  might allow local users to create or overwrite arbitrary files via a crafted
  --session-dir argument in conjunction with a symlink attack on the opd_pipe
  file, a different vulnerability than CVE-2011-1760.

CVE-2011-2472 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2472):
  Directory traversal vulnerability in utils/opcontrol in OProfile 0.9.6 and
  earlier might allow local users to overwrite arbitrary files via a .. (dot
  dot) in the --save argument, related to the --session-dir argument, a
  different vulnerability than CVE-2011-1760.

CVE-2011-2471 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2471):
  utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to
  gain privileges via shell metacharacters in the (1) --vmlinux, (2)
  --session-dir, or (3) --xen argument, related to the daemonrc file and the
  do_save_setup and do_load_setup functions, a different vulnerability than
  CVE-2011-1760.
Comment 1 Peter Volkov (RETIRED) gentoo-dev 2011-06-27 11:01:42 UTC
I think all this issues are covered by patches that were applied due to bug 366699. May be it's sane to resolve this bug as a duplicate and add information there...
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-07-03 16:16:22 UTC
(In reply to comment #1)
> I think all this issues are covered by patches that were applied due to bug
> 366699. May be it's sane to resolve this bug as a duplicate and add information
> there...

These issues appear to be fixed by oprofile-0.9.6-Do-additional-checks-on-user-supplied-arguments.patch. Peter, please correct me if I am wrong.

*** This bug has been marked as a duplicate of bug 366699 ***