Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200511-15 ] Smb4k: Local unauthorized file access
Date: Fri, 18 Nov 2005 15:22:55
Message-Id: 200511181610.17157.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200511-15
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Smb4k: Local unauthorized file access
9 Date: November 18, 2005
10 Bugs: #111089
11 ID: 200511-15
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability has been identified that allows unauthorized access to
19 the contents of /etc/sudoers and /etc/super.tab files.
20
21 Background
22 ==========
23
24 Smb4K is a SMB/CIFS share browser for KDE.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-misc/smb4k < 0.6.4 >= 0.6.4
33
34 Description
35 ===========
36
37 A vulnerability leading to unauthorized file access has been found. A
38 pre-existing symlink from /tmp/sudoers and /tmp/super.tab to a textfile
39 will cause Smb4k to write the contents of these files to the target of
40 the symlink, as Smb4k does not check for the existence of these files
41 before writing to them.
42
43 Impact
44 ======
45
46 An attacker could acquire local privilege escalation by adding
47 username(s) to the list of sudoers.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All smb4k users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=net-misc/smb4k-0.6.4"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2005-2851
66 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2851
67 [ 2 ] Smb4k Announcement
68 http://smb4k.berlios.de/
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200511-15.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2005 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.0