Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200411-26 ] GIMPS, SETI@home, ChessBrain: Insecure installation
Date: Wed, 17 Nov 2004 22:20:55
Message-Id: 200411172310.41306.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200411-26
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: GIMPS, SETI@home, ChessBrain: Insecure installation
9 Date: November 17, 2004
10 Bugs: #69868
11 ID: 200411-26
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Improper file ownership allows user-owned files to be run with root
19 privileges by init scripts.
20
21 Background
22 ==========
23
24 GIMPS is a client for the distributed Great Internet Mersenne Prime
25 Search. SETI@home is the client for the Search for Extraterrestrial
26 Intelligence (SETI) project. ChessBrain is the client for the
27 distributed chess supercomputer.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 app-sci/gimps <= 23.9 >= 23.9-r1
36 2 app-sci/setiathome <= 3.08-r3 >= 3.08-r4
37 *>= 3.03-r2
38 3 app-sci/chessbrain <= 20407 >= 20407-r1
39 -------------------------------------------------------------------
40 3 affected packages on all of their supported architectures.
41 -------------------------------------------------------------------
42
43 Description
44 ===========
45
46 GIMPS, SETI@home and ChessBrain ebuilds install user-owned binaries and
47 init scripts which are executed with root privileges.
48
49 Impact
50 ======
51
52 This could lead to a local privilege escalation or root compromise.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All GIMPS users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot --verbose ">=app-sci/gimps-23.9-r1"
66
67 All SETI@home users should upgrade to the latest version:
68
69 # emerge --sync
70 # emerge --ask --oneshot --verbose ">=app-sci/setiathome-3.08-r4"
71
72 All ChessBrain users should upgrade to the latest version:
73
74 # emerge --sync
75 # emerge --ask --oneshot --verbose ">=app-sci/chessbrain-20407-r1"
76
77 Availability
78 ============
79
80 This GLSA and any updates to it are available for viewing at
81 the Gentoo Security Website:
82
83 http://security.gentoo.org/glsa/glsa-200411-26.xml
84
85 Concerns?
86 =========
87
88 Security is a primary focus of Gentoo Linux and ensuring the
89 confidentiality and security of our users machines is of utmost
90 importance to us. Any security concerns should be addressed to
91 security@g.o or alternatively, you may file a bug at
92 http://bugs.gentoo.org.
93
94 License
95 =======
96
97 Copyright 2004 Gentoo Foundation, Inc; referenced text
98 belongs to its owner(s).
99
100 The contents of this document are licensed under the
101 Creative Commons - Attribution / Share Alike license.
102
103 http://creativecommons.org/licenses/by-sa/2.0