Bug 146290

Summary: CAN-2005-0011 buffer overflow in fliccd
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: kdeeduAssignee: Than Ngo <than>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: medium    
Version: 3CC: laroche, notting, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,embargoed=20050215
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-02-17 14:20:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-01-26 18:56:40 UTC
Erik Sjölund discovered that a buffer overflow in fliccd which is installed
setuid root can be exploited quite easily and will probably allow arbitrary code
to be executed.

We are waiting on a patch.

Comment 1 Josh Bressers 2005-01-26 18:57:17 UTC
This issue should also affect FC2.

Comment 2 Bill Nottingham 2005-01-26 21:40:32 UTC
The setuid bit should probably be turned off while we're there.

Comment 3 Than Ngo 2005-01-28 15:27:36 UTC
yes, it should be romoved in next rebuild

Comment 4 Than Ngo 2005-02-01 13:11:39 UTC
it's only effected in FC3! and is now fixed in kdeedu-3.3.1-2.2.

Comment 5 Mark J. Cox 2005-02-10 15:31:30 UTC
Dirk Mueller said: " the previous patch was bogus. I've updated the
bugs that were pointed out in it and diffed it against 3.3. Also, I
removed non-relevant chunks from the diff. 

I've noticed that there is no fliccd in KDE 3.2.x and older. This
means that the local-root vulnerability is restricted to KDE 3.3.x.
will do an updated  advisory tomorrow morning. 

public disclosure delayed until February 15"

Comment 6 Than Ngo 2005-02-10 15:52:02 UTC
yes, i have got this change. The new kdeedu-3.3.1-2.3, which i have
built 2 days ago in fc3-updates-candidate, has the correct fix ;-)

Comment 7 Mark J. Cox 2005-02-17 09:16:22 UTC
public, removing embargo.

Comment 8 Josh Bressers 2005-02-17 14:20:37 UTC
Pushed as FEDORA-2005-148
https://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html