Bug 1833042 (CVE-2020-10737)
Summary: | CVE-2020-10737 oddjob: race condition in oddjob_selinux_mkdir function in mkhomedir.c can lead to symlink attack | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Marco Benatto <mbenatto> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | abokovoy, nalin, rcritten |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | oddjob-0.34.5, oddjob-0.34.6 | Doc Type: | If docs needed, set a value |
Doc Text: |
A race condition was found in the mkhomedir tool shipped with the oddjob package. During the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2020-11-04 02:25:23 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1833043, 1833051, 1833052 | ||
Bug Blocks: | 1829972 |
Description
Marco Benatto
2020-05-07 17:29:04 UTC
Acknowledgments: Name: Matthias Gerstner (SUSE security team) Created oddjob tracking bugs for this issue: Affects: fedora-all [bug 1833043] Upstream commit for this issue: https://pagure.io/oddjob/c/10b8aaa1564b723a005b53acc069df71313f4cac?branch This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-10737 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4687 https://access.redhat.com/errata/RHSA-2020:4687 |