Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201709-11 ] GIMPS: Root privilege escalation
Date: Sun, 17 Sep 2017 19:08:26
Message-Id: 9912614.nGlseCyV4S@localhost.localdomain
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201709-11
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: GIMPS: Root privilege escalation
9 Date: September 17, 2017
10 Bugs: #603408
11 ID: 201709-11
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Gentoo's GIMPS ebuilds are vulnerable to privilege escalation due to
19 improper permissions. A local attacker could use it to gain root
20 privileges.
21
22 Background
23 ==========
24
25 GIMPS, the Great Internet Mersenne Prime Search, is a software capable
26 of find Mersenne Primes, which are used in cryptography. GIMPS is also
27 used for hardware testing.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 sci-mathematics/gimps < 28.10-r1 >= 28.10-r1
36
37 Description
38 ===========
39
40 It was discovered that Gentoo’s default GIMPS installation suffered
41 from a privilege escalation vulnerability in the init script. This
42 script calls an unsafe "chown -R" command in checkconfig() function.
43
44 Impact
45 ======
46
47 A local attacker who does not belong to the root group, but has the
48 ability to modify the /var/lib/gimps directory can escalate privileges
49 to the root group.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All GIMPS users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=sci-mathematics/gimps-28.10-r1"
63
64 References
65 ==========
66
67 [ 1 ] CVE-2017-14484
68 https://nvd.nist.gov/vuln/detail/CVE-2017-14484
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 https://security.gentoo.org/glsa/201709-11
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users' machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 https://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2017 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature