Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200405-05 ] Utempter symlink vulnerability
Date: Thu, 13 May 2004 16:14:13
Message-Id: 20040513161251.GI13780@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200405-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Utempter symlink vulnerability
9 Date: May 13, 2004
10 Bugs: #49536
11 ID: 200405-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Utempter contains a vulnerability that may allow local users to
19 overwrite arbitrary files via a symlink attack.
20
21 Background
22 ==========
23
24 Utempter is an application that allows non-privileged apps to write
25 utmp (login) info, which otherwise needs root access.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 sys-apps/utempter < 0.5.5.4 >= 0.5.5.4
34
35 Description
36 ===========
37
38 Utempter contains a vulnerability that may allow local users to
39 overwrite arbitrary files via a symlink attack.
40
41 Impact
42 ======
43
44 This vulnerability may allow arbitrary files to be overwritten with
45 root privileges.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time. All users are advised to
51 upgrade to the latest available version of utempter.
52
53 Resolution
54 ==========
55
56 All users of utempter should upgrade to the latest stable version:
57
58 # emerge sync
59
60 # emerge -pv ">=sys-apps/utempter-0.5.5.4"
61 # emerge ">=sys-apps/utempter-0.5.5.4"
62
63 References
64 ==========
65
66 [ 1 ] CAN-2004-0233
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0233
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-200405-05.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 http://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2004 Gentoo Technologies, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/1.0