Gentoo Archives: gentoo-announce

From: Stefan Behte <craig@g.o>
To: gentoo-announce@g.o, bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201009-08 ] python-updater: Untrusted search path
Date: Tue, 21 Sep 2010 22:41:48
Message-Id: 4C9926E2.3000302@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201009-08
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: python-updater: Untrusted search path
9 Date: September 21, 2010
10 Bugs: #288361
11 ID: 201009-08
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 An untrusted search path vulnerability in python-updater might result
19 in the execution of arbitrary code.
20
21 Background
22 ==========
23
24 python-updater is a script used to remerge python packages when
25 changing Python version.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 app-admin/python-updater < 0.7-r1 >= 0.7-r1
34
35 Description
36 ===========
37
38 Robert Buchholz of the Gentoo Security Team reported that
39 python-updater includes the current working directory and
40 subdirectories in the Python module search path (sys.path) before
41 calling "import".
42
43 Impact
44 ======
45
46 A local attacker could entice the root user to run "python-updater"
47 from a directory containing a specially crafted Python module,
48 resulting in the execution of arbitrary code with root privileges.
49
50 Workaround
51 ==========
52
53 Do not run "python-updater" from untrusted working directories.
54
55 Resolution
56 ==========
57
58 All python-updater users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=app-admin/python-updater-0.7-r1"
62
63 Availability
64 ============
65
66 This GLSA and any updates to it are available for viewing at
67 the Gentoo Security Website:
68
69 http://security.gentoo.org/glsa/glsa-201009-08.xml
70
71 Concerns?
72 =========
73
74 Security is a primary focus of Gentoo Linux and ensuring the
75 confidentiality and security of our users machines is of utmost
76 importance to us. Any security concerns should be addressed to
77 security@g.o or alternatively, you may file a bug at
78 https://bugs.gentoo.org.
79
80 License
81 =======
82
83 Copyright 2010 Gentoo Foundation, Inc; referenced text
84 belongs to its owner(s).
85
86 The contents of this document are licensed under the
87 Creative Commons - Attribution / Share Alike license.
88
89 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature