Bug 519436 (CVE-2008-6552)

Summary: CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: swhiteho
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-02-17 15:07:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 469338, 498950, 498951, 519686    
Bug Blocks:    

Description Tomas Hoger 2009-08-26 15:40:20 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-6552 to the following vulnerability:

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9. 

References:
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.html
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00164.html
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00165.html
http://secunia.com/advisories/32602/
http://xforce.iss.net/xforce/xfdb/46412
http://www.securityfocus.com/bid/32179

Comment 1 Steve Whitehouse 2009-08-27 07:49:51 UTC
Are you saying that the bug is already fixed, or that work remains to be done?

Comment 2 Tomas Hoger 2009-08-27 08:48:54 UTC
Fedora updates were pushed while ago, RHEL5 updates in 5.4 backport the fixes.  rgmanager's bits apply to RHEL4, so I plan to clone this bug and propose for inclusion in 4.9 updates.

Comment 3 Tomas Hoger 2009-08-27 09:21:57 UTC
For better clarity, here is a per-component list of changes relevant to this CVE:

cman:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=7a798fa3bc
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=6e8c492f8e

rgmanager - daemon part:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=3f03e42f0b

rgmanager - resource agents:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=18077be27b
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=5265ab0f6f
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=765f2dba9f
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=3daae0e957
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=4cc4d59283
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=8161a3c65a
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=d3ed649858
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=6c4fcfc77a

gfs2-utils:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=e06d163973
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=8d69822491
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=b75c1decdc


Note: some changes as backported to RHEL5 used approach different to upstream git commits (creating temporary files properly, not yet moving files to better locations under /var), e.g.:

http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=5bf3964b3b
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=684b86aa70
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=0b686fd6e0

Comment 5 errata-xmlrpc 2009-09-02 11:01:36 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1337 https://rhn.redhat.com/errata/RHSA-2009-1337.html

Comment 6 errata-xmlrpc 2009-09-02 11:03:22 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1339 https://rhn.redhat.com/errata/RHSA-2009-1339.html

Comment 7 errata-xmlrpc 2009-09-02 11:06:06 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1341 https://rhn.redhat.com/errata/RHSA-2009-1341.html

Comment 8 errata-xmlrpc 2009-09-02 12:12:21 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1337 https://rhn.redhat.com/errata/RHSA-2009-1337.html

Comment 9 errata-xmlrpc 2009-09-02 12:12:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1339 https://rhn.redhat.com/errata/RHSA-2009-1339.html

Comment 10 errata-xmlrpc 2009-09-02 12:12:37 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1341 https://rhn.redhat.com/errata/RHSA-2009-1341.html

Comment 11 Steve Whitehouse 2009-12-02 15:29:07 UTC
GFS2 doesn't exist in RHEL4 and so far as I can tell, all required changes are already in RHEL5. So as far as I can tell there is nothing left to do for gfs2-utils. Please confirm if that is the case.

Comment 12 Tomas Hoger 2009-12-02 15:35:26 UTC
Yes, looking at the depending bugs, no more action needed for gfs2-utils.

Comment 13 errata-xmlrpc 2011-02-16 15:07:09 UTC
This issue has been addressed in following products:

  CLuster Suite for RHEL 4

Via RHSA-2011:0264 https://rhn.redhat.com/errata/RHSA-2011-0264.html

Comment 14 errata-xmlrpc 2011-02-16 15:14:46 UTC
This issue has been addressed in following products:

  CLuster Suite for RHEL 4

Via RHSA-2011:0265 https://rhn.redhat.com/errata/RHSA-2011-0265.html