Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com, gentoo-core@l.g.o
Subject: [gentoo-announce] [ GLSA 200404-06 ] Util-linux login may leak sensitive data
Date: Wed, 07 Apr 2004 17:33:33
Message-Id: 20040407173235.GI16487@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200404-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Util-linux login may leak sensitive data
9
10 Date: April 07, 2004
11 Bugs: #46422
12 ID: 200404-06
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 The login program included in util-linux could leak sensitive
20 information under certain conditions.
21
22 Background
23 ==========
24
25 Util-linux is a suite of essential system utilites, including login,
26 agetty, fdisk.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 sys-apps/util-linux <= 2.11 >= 2.12
35
36 Description
37 ===========
38
39 In some situations the login program could leak sensitive data due to
40 an incorrect usage of a reallocated pointer.
41
42 NOTE: Only users who have PAM support disabled on their systems (i.e. -PAM in
43 their USE variable) will be affected by this vulnerability. By default, this
44 USE flag is enabled on all architectures. Users with PAM support on their
45 system receive login binaries as part of the pam-login package, which remains
46 unaffected.
47
48 Impact
49 ======
50
51 A remote attacker may obtain sensitive data.
52
53 Workaround
54 ==========
55
56 A workaround is not currently known for this issue. All users are advised to
57 upgrade to the latest version of the affected package.
58
59 Resolution
60 ==========
61
62 All util-linux users should upgrade to version 2.12 or later:
63
64 # emerge sync
65
66 # emerge -pv ">=sys-apps/util-linux-2.12"
67 # emerge ">=sys-apps/util-linux-2.12"
68
69 References
70 ==========
71
72 [ 1 ] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0080
73
74 Concerns?
75 =========
76
77 Security is a primary focus of Gentoo Linux and ensuring the
78 confidentiality and security of our users machines is of utmost
79 importance to us. Any security concerns should be addressed to
80 security@g.o or alternatively, you may file a bug at
81 http://bugs.gentoo.org.