Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200711-12 ] Tomboy: User-assisted execution of arbitrary code
Date: Thu, 08 Nov 2007 19:59:36
Message-Id: 473367A3.3000503@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200711-12
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Tomboy: User-assisted execution of arbitrary code
12 Date: November 08, 2007
13 Bugs: #189249
14 ID: 200711-12
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Tomboy doesn't properly handle environment variables, potentially
22 allowing a local attacker to execute arbitrary code.
23
24 Background
25 ==========
26
27 Tomboy is a GTK-based desktop note-taking application written in C# and
28 the Mono C#.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 app-misc/tomboy < 0.8.1-r1 >= 0.8.1-r1
37
38 Description
39 ===========
40
41 Jan Oravec reported that the "/usr/bin/tomboy" script sets the
42 "LD_LIBRARY_PATH" environment variable incorrectly, which might result
43 in the current working directory (.) to be included when searching for
44 dynamically linked libraries of the Mono Runtime application.
45
46 Impact
47 ======
48
49 A local attacker could entice a user into running Tomboy in a directory
50 containing a specially crafted library file to execute arbitrary code
51 with the privileges of the user running Tomboy.
52
53 Workaround
54 ==========
55
56 Do not run Tomboy from an untrusted working directory.
57
58 Resolution
59 ==========
60
61 All Tomboy users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=app-misc/tomboy-0.8.1-r1"
65
66 References
67 ==========
68
69 [ 1 ] CVE-2005-4790
70 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4790
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 http://security.gentoo.org/glsa/glsa-200711-12.xml
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 http://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2007 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.5
99 -----BEGIN PGP SIGNATURE-----
100 Version: GnuPG v1.4.7 (GNU/Linux)
101 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
102
103 iD8DBQFHM2ejuhJ+ozIKI5gRArn0AKCHGvQMfReygx+CNJswcgHC5ZLT/QCdGyyf
104 HMULjLPDCYXxaJG4YGh5hU8=
105 =SZnY
106 -----END PGP SIGNATURE-----
107 --
108 gentoo-announce@g.o mailing list