Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 552534 (CVE-2015-3248) - sys-libs/openhpi: world-readable /var/lib/openhpi directory
Summary: sys-libs/openhpi: world-readable /var/lib/openhpi directory
Status: RESOLVED FIXED
Alias: CVE-2015-3248
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2015-06-19 08:11 UTC by Agostino Sarubbo
Modified: 2016-12-31 14:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-06-19 08:11:20 UTC
From ${URL} :

openhpi ships with the /var/lib/openhpi/ directory set world readable and 
writeable. If this directory is used for storing the OPENHPI_UID_MAP or other
openhpi data for exam,p[le an attacker would be able to view, modify and delete 
it. Even without such usage an attacker could use it to fill up the storage
hosting the /var/lib/ directory if quotas are not properly set.

NOTE:
On Gentoo this is only world-readable instead of world-writable.


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-04-04 08:40:59 UTC
This is fixed upstream in >=3.6.0:

http://openhpi.org/Changelogs/3.6.0

@maintainer, please bump the package and cleanup the vulnerable versions.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-07-03 06:45:23 UTC
@maintainer, ping.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-11-20 12:24:55 UTC
@maintainer, any intention on bumping this?
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-11-25 15:43:39 UTC
@treecleaners, maintainer has expressed his intention of dropping the package.  Preferably clean the package or assign to maintainer-needed.
Comment 5 Pacho Ramos gentoo-dev 2016-12-31 13:51:15 UTC
dropped
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2016-12-31 14:42:50 UTC
Unstable package dropped.