oss-sec mailing list archives
Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)
From: Jan Lieskovsky <jlieskov () redhat com>
Date: Wed, 02 Jun 2010 14:25:01 +0200
Steve, Jan Lieskovsky wrote:
Hi Steve, vendors,Matt McCutchen pointed out a deficiency in the way rpm handled rpm package upgrades -- it failed to clear out the SUID/SGID bits of the old file by file replacement when privileged user performed package upgrade. Under certain circumstances, a local, authenticated user coulduse this flaw to escalate their privileges.
Maybe obvious and natural conclusion from previous post already, but Panu clarified yet, similar deficiency holds for dealing with posix file capabilities and SELinux contexts, i.e. they are not cleared after pkg upgrade. Not sure second CVE is needed for this, but if one is enough, wanted to explicitly mention this, so it can be described in the text of the CVE too. Thanks && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Red Hat Bugzilla entry: [1] https://bugzilla.redhat.com/show_bug.cgi?id=598775 Upstream changeset:[2] http://rpm.org/gitweb?p=rpm.git;a=commit;h=ca2d6b2b484f1501eafdde02e1688409340d2383Could you allocate CVE id for this? Thanks && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Current thread:
- CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Jan Lieskovsky (Jun 02)
- Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Jan Lieskovsky (Jun 02)
- Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Josh Bressers (Jun 03)
- Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Steven M. Christey (Jun 03)
- Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Panu Matilainen (Jun 03)
- Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Josh Bressers (Jun 03)
- Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Jan Lieskovsky (Jun 02)