Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200408-15 ] Tomcat: Insecure Installation
Date: Sun, 15 Aug 2004 15:33:37
Message-Id: 200408151730.12847.jaervosz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200408-15
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Tomcat: Insecure Installation
12 Date: August 15, 2004
13 Bugs: #59232
14 ID: 200408-15
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Improper file ownership may allow a member of the tomcat group to
22 execute scripts as root.
23
24 Background
25 ==========
26
27 Tomcat is the Apache Jakarta Project's official implementation of Java
28 Servlets and Java Server Pages.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 net-www/tomcat < 5.0.27-r3 >= 5.0.27-r3
37 *>= 4.1.30-r4
38 *>= 3.3.2-r2
39
40 Description
41 ===========
42
43 The Gentoo ebuild for Tomcat sets the ownership of the Tomcat init
44 scripts as tomcat:tomcat, but those scripts are executed with root
45 privileges when the system is started. This may allow a member of the
46 tomcat group to run arbitrary code with root privileges when the Tomcat
47 init scripts are run.
48
49 Impact
50 ======
51
52 This could lead to a local privilege escalation or root compromise by
53 authenticated users.
54
55 Workaround
56 ==========
57
58 Users may change the ownership of /etc/init.d/tomcat* and
59 /etc/conf.d/tomcat* to be root:root:
60
61 # chown -R root:root /etc/init.d/tomcat*
62 # chown -R root:root /etc/conf.d/tomcat*
63
64 Resolution
65 ==========
66
67 All Tomcat users can upgrade to the latest stable version, or simply
68 apply the workaround:
69
70 # emerge sync
71 # emerge -pv ">=net-www/tomcat-5.0.27-r3"
72 # emerge ">=net-www/tomcat-5.0.27-r3"
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-200408-15.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 http://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2004 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/1.0
101 -----BEGIN PGP SIGNATURE-----
102 Version: GnuPG v1.2.4 (GNU/Linux)
103
104 iD8DBQFBH4FfzKC5hMHO6rkRAjT7AJ9U2eXQGi5gGFRwokYJx2n/1Nv6mQCffn2w
105 FKP86R2pMqASV4enpi8UOu8=
106 =FhC/
107 -----END PGP SIGNATURE-----