Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1216962 - (CVE-2015-3159) CVE-2015-3159 abrt: missing process environment sanitizaton in abrt-action-install-debuginfo-to-abrt-cache
CVE-2015-3159 abrt: missing process environment sanitizaton in abrt-action-in...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20150429,repo...
: Security
Depends On: 1211966 1211967 1216973 1216974 1216975
Blocks: 1211224 1214172
  Show dependency treegraph
 
Reported: 2015-04-29 06:11 EDT by Florian Weimer
Modified: 2015-07-09 01:35 EDT (History)
9 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the abrt-action-install-debuginfo-to-abrt-cache helper program did not properly filter the process environment before invoking abrt-action-install-debuginfo. A local attacker could use this flaw to escalate their privileges on the system.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-09 01:35:53 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:1083 normal SHIPPED_LIVE Important: abrt security update 2015-06-09 19:48:24 EDT
Red Hat Product Errata RHSA-2015:1210 normal SHIPPED_LIVE Moderate: abrt security update 2015-07-07 08:39:40 EDT

  None (edit)
Description Florian Weimer 2015-04-29 06:11:49 EDT
It was discovered that the helper program,
abrt-action-install-debuginfo-to-abrt-cache, does not properly filter
the process environment (umask and truncated command line options)
before invoking abrt-action-install-debuginfo.  A local user could
exploit this vulnerability to obtain root privileges.

Acknowledgements:

This issue was discovered by Florian Weimer of Red Hat Product Security.
Comment 2 Florian Weimer 2015-04-29 06:38:09 EDT
Created abrt tracking bugs for this issue:

Affects: fedora-all [bug 1216975]
Comment 4 Florian Weimer 2015-04-29 06:50:30 EDT
The fix should set the umask to 022 and apply a whitelist to the command line options.

Changing the current directory to /var/spool/abrt would be preferable as well, but this is difficult because some ways of running abrt-action-install-debuginfo open a file build_ids in the current directory (which could result in an abrt -> local user information disclosure).  Perhaps the wrapper can open the file, using the calling user's UID/GID, and pass it on standard input.

I also looked at the way in which yum creates the /var/tmp/yum-abrt-* directory, and it appears to be okay.
Comment 6 Florian Weimer 2015-05-06 03:50:54 EDT
Starting with Red Hat Enterprise Linux 6.5, due to a regression introduced by the fix for bug 759443 (“ABRT won't install debuginfos from rhn repository”), abrt-action-install-debuginfo does not seem to do much when abrt-action-install-debuginfo-to-abrt-cache is invoked by a non-root user, so the issue is mitigated in later versions of Red Hat Enterprise Linux 6.
Comment 7 Jakub Filak 2015-05-06 06:44:51 EDT
I would like to fix abrt-action-install-debuginfo in RHEL-6 to make it working for non-root users too again (bug #1216962). Only the users who use only rhn repositories suffers from bug #756443 (“ABRT won't install debuginfos from rhn repository”), but other users who might have configured custom repositories (or CentOS users) should be able to use ABRT to download debug info packages.
Comment 10 errata-xmlrpc 2015-06-09 15:49:23 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:1083 https://rhn.redhat.com/errata/RHSA-2015-1083.html
Comment 11 errata-xmlrpc 2015-07-07 04:40:19 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2015:1210 https://rhn.redhat.com/errata/RHSA-2015-1210.html

Note You need to log in before you can comment on or make changes to this bug.