Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 463512 (CVE-2013-1910) - sys-apps/yum: Not removing bad metadata and using it in next run (CVE-2013-1910)
Summary: sys-apps/yum: Not removing bad metadata and using it in next run (CVE-2013-1910)
Status: RESOLVED FIXED
Alias: CVE-2013-1910
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-27 18:10 UTC by Agostino Sarubbo
Modified: 2013-09-17 22:01 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-03-27 18:10:42 UTC
From ${URL} :

  A security flaw was found in the way Yum package manager
performed management of repository metadata in certain
circumstances (bad metadata were not removed properly
and re-used in subsequent run). An attacker could inject
a specially-crafted Trojan horse file in the metadata of
a remote repository, possibly leading to their ability
to confuse Yum package manager to accept invalid untrusted
metadata as valid by mistake.

References:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=910446
[2] http://lists.fedoraproject.org/pipermail/package-announce/2013-March/099496.html
[3] http://lists.fedoraproject.org/pipermail/package-announce/2013-March/100299.html
[4] https://lwn.net/Articles/540426/ 
    (and search for 'yum: denial of service' here)

Relevant upstream patch:
[5] http://yum.baseurl.org/gitweb?p=yum.git;a=commitdiff;h=c148eb10b798270b3d15087433c8efb2a79a69d0
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-17 00:34:47 UTC
Upstream patch is there, waiting on a bump.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-17 22:01:16 UTC
Security bumped to 3.4.3_p20130218. ~ only, no stable. noglsa.