Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 389999 (CVE-2011-4129) - <net-libs/libsocialweb-0.25.20: Untrusted connection to Twitter via dbus (CVE-2011-4129)
Summary: <net-libs/libsocialweb-0.25.20: Untrusted connection to Twitter via dbus (CVE...
Status: RESOLVED FIXED
Alias: CVE-2011-4129
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-11-09 18:25 UTC by Michael Harrison
Modified: 2011-11-15 03:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Harrison 2011-11-09 18:25:55 UTC
From Red Hat mailing list:
Description of problem:
Whenever I boot I see a connection to twitter servers even though I didn't add
any online accounts ( and I don't have twitter ). I don't like nor want the web
services.

Not sure what version, so may be invalid









Reproducible: Always

Steps to Reproduce:
1.boot up
2.look at the connections
3.grep for "socialweb"
Actual Results:  
1 connection to some twitter server
tcp       28      0 10.10.18.71:48311           199.59.149.232:443         
CLOSE_WAIT  1529/libsocialweb-c 



Expected Results:  
NO CONNECTIONS
Comment 1 Alexandre Rostovtsev (RETIRED) gentoo-dev 2011-11-13 08:40:55 UTC
Should be fixed in libsocialweb-0.25.20. Note: the security impact of this is quite minor (see http://seclists.org/oss-sec/2011/q4/278) and all versions of libsocialweb are in ~arch, so I'm not sure if you really want to file a GLSA about this.

>  13 Nov 2011; Alexandre Rostovtsev <tetromino@gentoo.org>
>  -libsocialweb-0.25.18.ebuild, +libsocialweb-0.25.20.ebuild, metadata.xml:
>  Bump, port to EAPI4, drop old. Notable changes: should no longer silently
>  attempt to connect to Twitter and other services without the user's
>  permission (bug #389999, CVE-2011-4129, thanks to Michael Harrison
>  <n0idx80@gmail.com> for reporting).
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-11-15 03:39:48 UTC
(In reply to comment #1)
> Should be fixed in libsocialweb-0.25.20. 

Great, thank you. Closing noglsa for ~arch only package.