Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1325930 - (CVE-2016-3107) CVE-2016-3107 pulp: Node certificate containing private key stored in world-readable file
CVE-2016-3107 pulp: Node certificate containing private key stored in world-r...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160413,repor...
: Security
Depends On: 1326913 1326919
Blocks: 1325942
  Show dependency treegraph
 
Reported: 2016-04-11 08:41 EDT by Adam Mariš
Modified: 2018-09-19 11:16 EDT (History)
18 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was found that the private key for the node certificate was contained in a world-readable file. A local user could possibly use this flaw to gain access to the private key information in the file.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-09-19 15:02:37 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Proposed patch (1.37 KB, patch)
2016-04-11 08:43 EDT, Adam Mariš
no flags Details | Diff
Proposed patch (1.58 KB, patch)
2016-04-12 10:28 EDT, Randy Barlow
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Pulp Redmine 1842 Low CLOSED - WORKSFORME Test Redmine's Bugzilla Integration 2016-04-13 15:57 EDT

  None (edit)
Description Adam Mariš 2016-04-11 08:41:55 EDT
It was reported that Pulp node certificates containing private keys are stored in /etc/pki/pulp/nodes/ directory as world-readable.
Comment 1 Adam Mariš 2016-04-11 08:42:03 EDT
Acknowledgments:

Name: Randy Barlow (Red Hat), Jeremy Cline (Red Hat)
Comment 2 Adam Mariš 2016-04-11 08:43 EDT
Created attachment 1145987 [details]
Proposed patch
Comment 3 Randy Barlow 2016-04-12 10:28 EDT
Created attachment 1146471 [details]
Proposed patch

I am amending the proposed patch to use the -Z flag on mv, and to credit jcline in the commit message for independently reporting the issue.
Comment 4 Randy Barlow 2016-04-13 12:48:20 EDT
This issue is filed upstream as #1833 and is fixed by PR #2529:

https://pulp.plan.io/issues/1833
https://github.com/pulp/pulp/pull/2529
Comment 7 pulp-infra@redhat.com 2016-04-13 15:57:12 EDT
The Pulp upstream bug status is at CLOSED - WORKSFORME. Updating the external tracker on this bug.
Comment 8 pulp-infra@redhat.com 2016-04-13 15:57:18 EDT
The Pulp upstream bug priority is at Low. Updating the external tracker on this bug.
Comment 9 Kurt Seifried 2016-09-19 15:02:37 EDT
This issue has been addressed in the following products:

  Red Hat Satellite 6.2

Via RHSA-2016:1501

Note You need to log in before you can comment on or make changes to this bug.