View previous topic :: View next topic |
Author |
Message |
GLSA Bodhisattva
Joined: 25 Feb 2003 Posts: 3829 Location: Essen, Germany
|
Posted: Thu Nov 18, 2004 5:16 am Post subject: [ GLSA 200411-26 ] GIMPS, SETI@home, ChessBrain: Insecure in |
|
|
Gentoo Linux Security Advisory
Title: GIMPS, SETI@home, ChessBrain: Insecure installation (GLSA 200411-26)
Severity: high
Exploitable: local
Date: November 17, 2004
Updated: May 22, 2006
Bug(s): #69868
ID: 200411-26
Synopsis
Improper file ownership allows user-owned files to be run with root privileges by init scripts.
Background
GIMPS is a client for the distributed Great Internet Mersenne Prime Search. SETI@home is the client for the Search for Extraterrestrial Intelligence (SETI) project. ChessBrain is the client for the distributed chess supercomputer.
Affected Packages
Package: sci-misc/gimps
Vulnerable: <= 23.9
Unaffected: >= 23.9-r1
Architectures: All supported architectures
Package: sci-misc/setiathome
Vulnerable: <= 3.08-r3
Unaffected: >= 3.08-r4
Unaffected: >= 3.03-r2 < 3.4
Architectures: All supported architectures
Package: sci-misc/chessbrain
Vulnerable: <= 20407
Unaffected: >= 20407-r1
Architectures: All supported architectures
Description
GIMPS, SETI@home and ChessBrain ebuilds install user-owned binaries and init scripts which are executed with root privileges.
Impact
This could lead to a local privilege escalation or root compromise.
Workaround
There is no known workaround at this time.
Resolution
All GIMPS users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=sci-misc/gimps-23.9-r1" | All SETI@home users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=sci-misc/setiathome-3.03-r2" | All ChessBrain users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=sci-misc/chessbrain-20407-r1" |
References
CVE-2004-1115
CVE-2004-1116
CVE-2004-1117
Last edited by GLSA on Tue May 23, 2006 4:18 am; edited 2 times in total |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|