Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200504-12 ] rsnapshot: Local privilege escalation
Date: Wed, 13 Apr 2005 18:10:08
Message-Id: 425D607F.1010701@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200504-12
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: rsnapshot: Local privilege escalation
9 Date: April 13, 2005
10 Bugs: #88681
11 ID: 200504-12
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 rsnapshot allow a local user to take ownership of local files,
19 resulting in privilege escalation.
20
21 Background
22 ==========
23
24 rsnapshot is a filesystem snapshot utility based on rsync, allowing
25 local and remote systems backups.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-misc/rsnapshot < 1.2.1 >= 1.2.1
34
35 Description
36 ===========
37
38 The copy_symlink() subroutine in rsnapshot follows symlinks when
39 changing file ownership, instead of changing the ownership of the
40 symlink itself.
41
42 Impact
43 ======
44
45 Under certain circumstances, local attackers can exploit this
46 vulnerability to take ownership of arbitrary files, resulting in local
47 privilege escalation.
48
49 Workaround
50 ==========
51
52 The copy_symlink() subroutine is not called if the cmd_cp parameter has
53 been enabled.
54
55 Resolution
56 ==========
57
58 All rsnapshot users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=net-misc/rsnapshot-1.2.1"
62
63 References
64 ==========
65
66 [ 1 ] rsnapshot Security Advisory 001
67 http://www.rsnapshot.org/security/2005/001.html
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-200504-12.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 http://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2005 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.0

Attachments

File name MIME type
signature.asc application/pgp-signature