Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 711332 (CVE-2019-13313) - <sys-libs/libosinfo-1.6.0: Credential leak (CVE-2019-13313)
Summary: <sys-libs/libosinfo-1.6.0: Credential leak (CVE-2019-13313)
Alias: CVE-2019-13313
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: B4 [noglsa cve]
Depends on:
Reported: 2020-03-02 16:34 UTC by Sam James
Modified: 2020-03-15 02:16 UTC (History)
1 user (show)

See Also:
Package list:
sys-apps/osinfo-db-tools-1.6.0-r1 sys-libs/libosinfo-1.6.0 sys-apps/osinfo-db-20200214
Runtime testing required: ---
stable-bot: sanity-check+


Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-02 16:34:45 UTC
"libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line."
Comment 1 Mart Raudsepp gentoo-dev 2020-03-02 16:43:52 UTC
1.6.0 appears to just deprecate this way of passing the credentials. Now what is actually passing them like that is the real question, I'd think.
I don't mind stabilizing a newer version on the pretext of security, but that doesn't mean other stuff calling osinfo-install-script now suddenly doesn't put the password into the process commandline anymore.
Comment 2 Mart Raudsepp gentoo-dev 2020-03-02 16:54:40 UTC
So lets stable anyways as we are so behind on libosinfo, and there have been no bug reports that I know of for a week for this version.
osinfo-db I usually ALLARCHES myself, but due to the huge jump and some test cases moving churn upstream lets include it in the batch without ALLARCHES this time.
Comment 3 Agostino Sarubbo gentoo-dev 2020-03-03 11:46:45 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2020-03-03 12:39:59 UTC
amd64 stable
Comment 5 Mart Raudsepp gentoo-dev 2020-03-12 14:12:20 UTC
arm64 stable
Comment 6 Thomas Deutschmann gentoo-dev 2020-03-15 02:16:43 UTC
Repository is clean, all done!