Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 519436 - (CVE-2008-6552) CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues
CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file u...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,source=redhat,reported=200...
: Security
Depends On: 469338 498950 498951 519686
Blocks:
  Show dependency treegraph
 
Reported: 2009-08-26 11:40 EDT by Tomas Hoger
Modified: 2016-03-04 07:47 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-02-17 10:07:51 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1337 normal SHIPPED_LIVE Low: gfs2-utils security and bug fix update 2009-09-01 06:41:56 EDT
Red Hat Product Errata RHSA-2009:1339 normal SHIPPED_LIVE Low: rgmanager security, bug fix, and enhancement update 2009-09-01 06:42:29 EDT
Red Hat Product Errata RHSA-2009:1341 normal SHIPPED_LIVE Low: cman security, bug fix, and enhancement update 2009-09-01 06:43:16 EDT
Red Hat Product Errata RHSA-2011:0264 normal SHIPPED_LIVE Low: rgmanager security and bug fix update 2011-02-16 10:07:04 EST
Red Hat Product Errata RHSA-2011:0265 normal SHIPPED_LIVE Low: ccs security update 2011-02-16 10:14:42 EST

  None (edit)
Description Tomas Hoger 2009-08-26 11:40:20 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-6552 to the following vulnerability:

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9. 

References:
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.html
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00164.html
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00165.html
http://secunia.com/advisories/32602/
http://xforce.iss.net/xforce/xfdb/46412
http://www.securityfocus.com/bid/32179
Comment 1 Steve Whitehouse 2009-08-27 03:49:51 EDT
Are you saying that the bug is already fixed, or that work remains to be done?
Comment 2 Tomas Hoger 2009-08-27 04:48:54 EDT
Fedora updates were pushed while ago, RHEL5 updates in 5.4 backport the fixes.  rgmanager's bits apply to RHEL4, so I plan to clone this bug and propose for inclusion in 4.9 updates.
Comment 3 Tomas Hoger 2009-08-27 05:21:57 EDT
For better clarity, here is a per-component list of changes relevant to this CVE:

cman:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=7a798fa3bc
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=6e8c492f8e

rgmanager - daemon part:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=3f03e42f0b

rgmanager - resource agents:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=18077be27b
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=5265ab0f6f
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=765f2dba9f
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=3daae0e957
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=4cc4d59283
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=8161a3c65a
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=d3ed649858
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=6c4fcfc77a

gfs2-utils:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=e06d163973
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=8d69822491
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=b75c1decdc


Note: some changes as backported to RHEL5 used approach different to upstream git commits (creating temporary files properly, not yet moving files to better locations under /var), e.g.:

http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=5bf3964b3b
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=684b86aa70
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=0b686fd6e0
Comment 5 errata-xmlrpc 2009-09-02 07:01:36 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1337 https://rhn.redhat.com/errata/RHSA-2009-1337.html
Comment 6 errata-xmlrpc 2009-09-02 07:03:22 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1339 https://rhn.redhat.com/errata/RHSA-2009-1339.html
Comment 7 errata-xmlrpc 2009-09-02 07:06:06 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1341 https://rhn.redhat.com/errata/RHSA-2009-1341.html
Comment 8 errata-xmlrpc 2009-09-02 08:12:21 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1337 https://rhn.redhat.com/errata/RHSA-2009-1337.html
Comment 9 errata-xmlrpc 2009-09-02 08:12:27 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1339 https://rhn.redhat.com/errata/RHSA-2009-1339.html
Comment 10 errata-xmlrpc 2009-09-02 08:12:37 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1341 https://rhn.redhat.com/errata/RHSA-2009-1341.html
Comment 11 Steve Whitehouse 2009-12-02 10:29:07 EST
GFS2 doesn't exist in RHEL4 and so far as I can tell, all required changes are already in RHEL5. So as far as I can tell there is nothing left to do for gfs2-utils. Please confirm if that is the case.
Comment 12 Tomas Hoger 2009-12-02 10:35:26 EST
Yes, looking at the depending bugs, no more action needed for gfs2-utils.
Comment 13 errata-xmlrpc 2011-02-16 10:07:09 EST
This issue has been addressed in following products:

  CLuster Suite for RHEL 4

Via RHSA-2011:0264 https://rhn.redhat.com/errata/RHSA-2011-0264.html
Comment 14 errata-xmlrpc 2011-02-16 10:14:46 EST
This issue has been addressed in following products:

  CLuster Suite for RHEL 4

Via RHSA-2011:0265 https://rhn.redhat.com/errata/RHSA-2011-0265.html

Note You need to log in before you can comment on or make changes to this bug.