Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 406655 (CVE-2012-0871) - =sys-apps/systemd-{37,38}-r*: X11 Session File Creation Weakness (CVE-2012-0871)
Summary: =sys-apps/systemd-{37,38}-r*: X11 Session File Creation Weakness (CVE-2012-0871)
Status: RESOLVED FIXED
Alias: CVE-2012-0871
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/48208/
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-03-02 20:20 UTC by Agostino Sarubbo
Modified: 2012-03-05 15:54 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-03-02 20:20:32 UTC
From secunia security advisory at $URL:

Description:
The weakness is caused due to the systemd-logind component insecurely creating a X11 session file (/run/user/<username>/X11/display) and can be exploited to create a symlink inside arbitrary directories.

The weakness is reported in versions prior to 39.


Solution
Update to version 39 or later.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2012-03-04 13:55:16 UTC
I see two solutions here. Either:
a) mask older systemd versions (=> all systemd versions in tree will be hard-masked for one reason or other),
b) backport a patch.

Could you point to a specific commit in systemd git?
Comment 3 Agostino Sarubbo gentoo-dev 2012-03-04 14:27:17 UTC
(In reply to comment #1)
> Could you point to a specific commit in systemd git?

Btw, this issue is fixed in systemd-39.

I guess you can backport it in our ~arch version.
Comment 4 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2012-03-04 19:39:39 UTC
Ah, it's in logind. I guess that would make only our -37 & -38 vulnerable.

Will it be enough to drop the offending versions?
Comment 5 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2012-03-05 08:50:34 UTC
And removed.
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2012-03-05 15:54:27 UTC
Great, thank you. Closing noglsa.