Bug 523178 (CVE-2010-0746)

Summary: CVE-2010-0746 DeviceKit: Privilege escalation via pluggable storage device labels
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: mclasen, security-response-team, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-19 09:09:04 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 572296    
Bug Blocks:    

Description Jan Lieskovsky 2009-09-14 11:59:19 UTC
A privilege escalation flaw was found in the way DeviceKit used to handle
labels for pluggable storage devices. A local, unprivileged user could
provide a specially-crafted string as a name, for the newly created / added
system device, leading to escalation of his privileges.

Upstream bug report:
--------------------
http://bugs.freedesktop.org/show_bug.cgi?id=23235

Upstream patch:
---------------
http://cgit.freedesktop.org/DeviceKit/DeviceKit-disks/commit/?id=62f883c7d38e75d0669c162529062a1e81d00da2

Comment 3 Jan Lieskovsky 2009-09-16 13:26:06 UTC
This issue affects the versions of DeviceKit-disks package, as shipped
with Fedora releases of 10 and 11 (DeviceKit-disks-002-1.git20080720.fc10
and DeviceKit-disks-004-4.fc11).

Comment 7 Vincent Danen 2010-03-10 19:03:12 UTC
This is corrected in the upstream version of DeviceKit-disks as shipped with Fedora 12.  It is not fixed in Fedora 11.

Comment 9 Jan Lieskovsky 2010-04-03 16:06:40 UTC
This is CVE-2010-0746.

Comment 10 Vincent Danen 2010-04-06 19:38:09 UTC
An exploit/proof-of-concept for this is now public:

http://xorl.wordpress.com/2010/04/06/cve-2010-0746-devicekit-local-privilege-escalation/