Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200701-19 ] OpenLDAP: Insecure usage of /tmp during installation
Date: Tue, 23 Jan 2007 23:09:55
Message-Id: 20070123223807.GD28520@falco.falcal.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200701-19
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: OpenLDAP: Insecure usage of /tmp during installation
9 Date: January 23, 2007
10 Bugs: #159508
11 ID: 200701-19
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A shell script commonly released with OpenLDAP makes insecure usage of
19 files in /tmp during the emerge process.
20
21 Background
22 ==========
23
24 OpenLDAP Software is an open source implementation of the Lightweight
25 Directory Access Protocol.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-nds/openldap < 2.1.30-r10 >= 2.1.30-r10
34 >= 2.2.28-r7
35 >= 2.3.30-r2
36 net-nds/openldap < 2.2.28-r7 >= 2.1.30-r10
37 >= 2.2.28-r7
38 >= 2.3.30-r2
39 net-nds/openldap < 2.3.30-r2 >= 2.1.30-r10
40 >= 2.2.28-r7
41 >= 2.3.30-r2
42
43 Description
44 ===========
45
46 Tavis Ormandy of the Gentoo Linux Security Team has discovered that the
47 file gencert.sh distributed with the Gentoo ebuild for OpenLDAP does
48 not exit upon the existence of a directory in /tmp during installation
49 allowing for directory traversal.
50
51 Impact
52 ======
53
54 A local attacker could create a symbolic link in /tmp and potentially
55 overwrite arbitrary system files upon a privileged user emerging
56 OpenLDAP.
57
58 Workaround
59 ==========
60
61 There is no known workaround at this time.
62
63 Resolution
64 ==========
65
66 All OpenLDAP users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose "net-nds/openldap"
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-200701-19.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 http://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2007 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/2.5