Bug 146290 - CAN-2005-0011 buffer overflow in fliccd
Summary: CAN-2005-0011 buffer overflow in fliccd
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: kdeedu
Version: 3
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Than Ngo
QA Contact:
URL:
Whiteboard: impact=important,embargoed=20050215
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-01-26 18:56 UTC by Josh Bressers
Modified: 2007-11-30 22:10 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-02-17 14:20:37 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2005-01-26 18:56:40 UTC
Erik Sjölund discovered that a buffer overflow in fliccd which is installed
setuid root can be exploited quite easily and will probably allow arbitrary code
to be executed.

We are waiting on a patch.

Comment 1 Josh Bressers 2005-01-26 18:57:17 UTC
This issue should also affect FC2.

Comment 2 Bill Nottingham 2005-01-26 21:40:32 UTC
The setuid bit should probably be turned off while we're there.

Comment 3 Than Ngo 2005-01-28 15:27:36 UTC
yes, it should be romoved in next rebuild

Comment 4 Than Ngo 2005-02-01 13:11:39 UTC
it's only effected in FC3! and is now fixed in kdeedu-3.3.1-2.2.

Comment 5 Mark J. Cox 2005-02-10 15:31:30 UTC
Dirk Mueller said: " the previous patch was bogus. I've updated the
bugs that were pointed out in it and diffed it against 3.3. Also, I
removed non-relevant chunks from the diff. 

I've noticed that there is no fliccd in KDE 3.2.x and older. This
means that the local-root vulnerability is restricted to KDE 3.3.x.
will do an updated  advisory tomorrow morning. 

public disclosure delayed until February 15"

Comment 6 Than Ngo 2005-02-10 15:52:02 UTC
yes, i have got this change. The new kdeedu-3.3.1-2.3, which i have
built 2 days ago in fc3-updates-candidate, has the correct fix ;-)

Comment 7 Mark J. Cox 2005-02-17 09:16:22 UTC
public, removing embargo.

Comment 8 Josh Bressers 2005-02-17 14:20:37 UTC
Pushed as FEDORA-2005-148
https://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html


Note You need to log in before you can comment on or make changes to this bug.