Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200512-07 ] OpenLDAP, Gauche: RUNPATH issues
Date: Thu, 15 Dec 2005 12:23:41
Message-Id: 43A15D47.1000702@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200512-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: OpenLDAP, Gauche: RUNPATH issues
9 Date: December 15, 2005
10 Bugs: #105380, #112577
11 ID: 200512-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 OpenLDAP and Gauche suffer from RUNPATH issues that may allow users in
19 the "portage" group to escalate privileges.
20
21 Background
22 ==========
23
24 OpenLDAP is a suite of LDAP-related application and development tools.
25 Gauche is an R5RS Scheme interpreter.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-nds/openldap < 2.2.28-r3 >= 2.2.28-r3
34 *>= 2.1.30-r6
35 2 dev-lang/gauche < 0.8.6-r1 >= 0.8.6-r1
36 -------------------------------------------------------------------
37 2 affected packages on all of their supported architectures.
38 -------------------------------------------------------------------
39
40 Description
41 ===========
42
43 Gentoo packaging for OpenLDAP and Gauche may introduce insecure paths
44 into the list of directories that are searched for libraries at
45 runtime.
46
47 Impact
48 ======
49
50 A local attacker, who is a member of the "portage" group, could create
51 a malicious shared object in the Portage temporary build directory that
52 would be loaded at runtime by a dependent binary, potentially resulting
53 in privilege escalation.
54
55 Workaround
56 ==========
57
58 Only grant "portage" group rights to trusted users.
59
60 Resolution
61 ==========
62
63 All OpenLDAP users should upgrade to the latest version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose net-nds/openldap
67
68 All Gauche users should upgrade to the latest version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=dev-lang/gauche-0.8.6-r1"
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 http://security.gentoo.org/glsa/glsa-200512-07.xml
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 http://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2005 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 http://creativecommons.org/licenses/by-sa/2.0

Attachments

File name MIME type
signature.asc application/pgp-signature