Bug 757171 (CVE-2011-4349)

Summary: CVE-2011-4349 colord: Multiple SQL injection flaws in database routines processing color device mappings and devices
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: hughsient, rhughes
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20110906,reported=20111125,source=oss-security,cvss2=3.3/AV:L/AC:M/Au:N/C:N/I:P/A:P,fedora-all/colord=affected
Fixed In Version: colord-0.1.15-1.fc16 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-05-27 18:07:02 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 757173    
Bug Blocks:    

Description Jan Lieskovsky 2011-11-25 11:46:44 EST
Multiple SQL injection flaws were found in the way colord, a color daemon that maps color devices to color profiles in the system context, performed SQL queries sanitization in database routines processing color device mappings and devices. If a local user was allowed to create new devices, and colord daemon was run as root, a local attacker could use this flaw to corrupt colord's own database or potentially other system SQLite3 based and related databases (for example that, used by polkit daemon).

References:
[1] https://bugs.freedesktop.org/show_bug.cgi?id=42904
[2] https://bugzilla.novell.com/show_bug.cgi?id=698250
[3] http://www.openwall.com/lists/oss-security/2011/11/25/1

Relevant upstream patches:
[4] http://gitorious.org/colord/master/commit/1fadd90afcb4bbc47513466ee9bb1e4a8632ac3b
[5] http://gitorious.org/colord/master/commit/36549e0ed255e7dfa7852d08a75dd5f00cbd270e
Comment 1 Jan Lieskovsky 2011-11-25 11:47:51 EST
These issues affect the versions of the colord package, as shipped with Fedora release of 15 and 16. Please schedule an update.
Comment 2 Jan Lieskovsky 2011-11-25 11:48:43 EST
Created colord tracking bugs for this issue

Affects: fedora-all [bug 757173]
Comment 3 Jan Lieskovsky 2011-11-25 11:59:57 EST
The CVE identifier of CVE-2011-4349 has been assigned to these issues:
http://www.openwall.com/lists/oss-security/2011/11/25/4
Comment 4 Richard Hughes 2011-11-26 04:02:20 EST
I've just done an upstream release and am building new packages now.

Richard.
Comment 5 Richard Hughes 2011-11-26 04:29:42 EST
Built for F15, F16 and rawhide and then submitted as updates as https://admin.fedoraproject.org/updates/colord-0.1.15-1.fc15 and https://admin.fedoraproject.org/updates/colord-0.1.15-1.fc16
Comment 6 Jan Lieskovsky 2011-11-27 11:07:42 EST
(In reply to comment #4)
> I've just done an upstream release and am building new packages now.

Brilliant, thank you for that.

Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

> 
> Richard.
Comment 7 Fedora Update System 2011-12-03 21:46:50 EST
colord-0.1.15-1.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.