Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 197701 (CVE-2007-5751) - net-news/liferea Insecure backup file permission (CVE-2007-5751)
Summary: net-news/liferea Insecure backup file permission (CVE-2007-5751)
Status: RESOLVED FIXED
Alias: CVE-2007-5751
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27438
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-10-31 23:57 UTC by Robert Buchholz (RETIRED)
Modified: 2007-12-02 12:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-10-31 23:57:37 UTC
CVE-2007-5751 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5751):
  Liferea before 1.4.6 uses weak permissions (0644) for the feedlist.opml
  backup file, which allows local users to obtain credentials.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-10-31 23:59:15 UTC
Daniel, please advise.
Comment 2 Daniel Gryniewicz (RETIRED) gentoo-dev 2007-11-01 02:16:12 UTC
I've checked this, and the backup file only has bad perms in the 1.4.x series (which is not stable anywhere), and is in a subdirectory with 700 perms. so it's probably not an issue.  I'll bump 1.4.5b to 1.4.6 anyway, which should take care of this problem.
Comment 3 Daniel Gryniewicz (RETIRED) gentoo-dev 2007-11-01 02:17:13 UTC
No, I take it back.  The 1.2 series also has 0644 perms (again in a 0700 directory).  I'll find and backport the fix, as 1.4.x is nowhere near ready to go stable.
Comment 4 Daniel Gryniewicz (RETIRED) gentoo-dev 2007-11-01 03:09:03 UTC
Okay, 1.4.6 is in the tree (and 1.4.5b removed).  In addition, I backported the patch fixing the perms to 1.2.23-r1.  I don't recommend that 1.4.x go stable at this point, so if early stabilization is necessary, 1.2.23-r1 is the correct version.

I did check, and the patch the fix the perms on the backup file on the next run.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2007-11-01 23:27:19 UTC
Thanks.

Arches, please test and mark stable net-news/liferea-1.2.23-r1.
Target keywords : "amd64 ppc ppc64 sparc x86"
Comment 6 Dawid Węgliński (RETIRED) gentoo-dev 2007-11-02 01:11:08 UTC
FFS:

  DEPEND.bad                     1
   net-news/liferea/liferea-1.2.23.ebuild: ppc64(default-linux/ppc/ppc64/2006.1/64bit-userland) ['net-misc/networkmanager']

Comment 7 Dawid Węgliński (RETIRED) gentoo-dev 2007-11-02 15:19:46 UTC
x86 stable
Comment 8 Raúl Porcel (RETIRED) gentoo-dev 2007-11-02 15:26:55 UTC
sparc stable
Comment 9 Markus Rothe (RETIRED) gentoo-dev 2007-11-03 21:56:55 UTC
masked networkmanager use flag and marked stable on ppc64
Comment 10 Tobias Scherbaum (RETIRED) gentoo-dev 2007-11-06 18:03:06 UTC
ppc stable
Comment 11 Steve Dibb (RETIRED) gentoo-dev 2007-11-14 03:43:03 UTC
amd64 stable
Comment 12 Robert Buchholz (RETIRED) gentoo-dev 2007-11-14 17:46:27 UTC
Vote now open.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-20 22:11:55 UTC
voting NO wrt comment #2
Comment 14 Robert Buchholz (RETIRED) gentoo-dev 2007-12-02 12:45:37 UTC
robert@joel ~ $ cat /home/rbu/.liferea_1.2/feedlist.opml.backup
cat: /home/rbu/.liferea_1.2/feedlist.opml.backup: Permission denied

Voting NO and closing.