Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1292432 - (CVE-2015-1336) CVE-2015-1336 man-db: TOCTOU bug when processing catman pages
CVE-2015-1336 man-db: TOCTOU bug when processing catman pages
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20151213,repor...
: Security
Depends On: 1292433
Blocks: 1292434
  Show dependency treegraph
 
Reported: 2015-12-17 07:49 EST by Martin Prpič
Modified: 2016-07-11 09:34 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-06-07 02:22:58 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2015-12-17 07:49:01 EST
The following flaw was found in man-db:

The daily mandb cleanup job for old catman pages changes the permissions of all non-man files to user man.

Originally filed against Ubuntu:

https://bugs.launchpad.net/ubuntu/+source/man-db/+bug/1482786

External References:

http://www.halfdog.net/Security/2015/MandbSymlinkLocalRootPrivilegeEscalation/
Comment 1 Martin Prpič 2015-12-17 07:49:30 EST
Created man-db tracking bugs for this issue:

Affects: fedora-all [bug 1292433]
Comment 2 Nikola Forró 2016-01-04 08:26:06 EST
Hello,

It appears to me that Fedora and RHEL7 man-db packages are not affected by this, since there is no cleanup job for old catman pages there:
http://pkgs.fedoraproject.org/cgit/man-db.git/tree/man-db.crondaily?h=f23
Comment 3 Doran Moppert 2016-06-07 02:15:54 EDT
Nikola's comment above is correct:  man-db in rhel and fedora are not
affected.  The man-db crontab in both doesn't chown thus lacks the
TOCTOU issue, plus (at least on rhel) /var/cache/man lacks the setgid
bit which makes the other part of this attack possible.

Note You need to log in before you can comment on or make changes to this bug.