Bug 519436 (CVE-2008-6552) - CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues
Summary: CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file u...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2008-6552
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 469338 498950 498951 519686
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-08-26 15:40 UTC by Tomas Hoger
Modified: 2019-09-29 12:31 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-02-17 15:07:51 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1337 0 normal SHIPPED_LIVE Low: gfs2-utils security and bug fix update 2009-09-01 10:41:56 UTC
Red Hat Product Errata RHSA-2009:1339 0 normal SHIPPED_LIVE Low: rgmanager security, bug fix, and enhancement update 2009-09-01 10:42:29 UTC
Red Hat Product Errata RHSA-2009:1341 0 normal SHIPPED_LIVE Low: cman security, bug fix, and enhancement update 2009-09-01 10:43:16 UTC
Red Hat Product Errata RHSA-2011:0264 0 normal SHIPPED_LIVE Low: rgmanager security and bug fix update 2011-02-16 15:07:04 UTC
Red Hat Product Errata RHSA-2011:0265 0 normal SHIPPED_LIVE Low: ccs security update 2011-02-16 15:14:42 UTC

Description Tomas Hoger 2009-08-26 15:40:20 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-6552 to the following vulnerability:

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9. 

References:
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.html
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00164.html
http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00165.html
http://secunia.com/advisories/32602/
http://xforce.iss.net/xforce/xfdb/46412
http://www.securityfocus.com/bid/32179

Comment 1 Steve Whitehouse 2009-08-27 07:49:51 UTC
Are you saying that the bug is already fixed, or that work remains to be done?

Comment 2 Tomas Hoger 2009-08-27 08:48:54 UTC
Fedora updates were pushed while ago, RHEL5 updates in 5.4 backport the fixes.  rgmanager's bits apply to RHEL4, so I plan to clone this bug and propose for inclusion in 4.9 updates.

Comment 3 Tomas Hoger 2009-08-27 09:21:57 UTC
For better clarity, here is a per-component list of changes relevant to this CVE:

cman:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=7a798fa3bc
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=6e8c492f8e

rgmanager - daemon part:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=3f03e42f0b

rgmanager - resource agents:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=18077be27b
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=5265ab0f6f
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=765f2dba9f
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=3daae0e957
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=4cc4d59283
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=8161a3c65a
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=d3ed649858
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=6c4fcfc77a

gfs2-utils:
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=e06d163973
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=8d69822491
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=b75c1decdc


Note: some changes as backported to RHEL5 used approach different to upstream git commits (creating temporary files properly, not yet moving files to better locations under /var), e.g.:

http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=5bf3964b3b
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=684b86aa70
http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=0b686fd6e0

Comment 5 errata-xmlrpc 2009-09-02 11:01:36 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1337 https://rhn.redhat.com/errata/RHSA-2009-1337.html

Comment 6 errata-xmlrpc 2009-09-02 11:03:22 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1339 https://rhn.redhat.com/errata/RHSA-2009-1339.html

Comment 7 errata-xmlrpc 2009-09-02 11:06:06 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1341 https://rhn.redhat.com/errata/RHSA-2009-1341.html

Comment 8 errata-xmlrpc 2009-09-02 12:12:21 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1337 https://rhn.redhat.com/errata/RHSA-2009-1337.html

Comment 9 errata-xmlrpc 2009-09-02 12:12:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1339 https://rhn.redhat.com/errata/RHSA-2009-1339.html

Comment 10 errata-xmlrpc 2009-09-02 12:12:37 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1341 https://rhn.redhat.com/errata/RHSA-2009-1341.html

Comment 11 Steve Whitehouse 2009-12-02 15:29:07 UTC
GFS2 doesn't exist in RHEL4 and so far as I can tell, all required changes are already in RHEL5. So as far as I can tell there is nothing left to do for gfs2-utils. Please confirm if that is the case.

Comment 12 Tomas Hoger 2009-12-02 15:35:26 UTC
Yes, looking at the depending bugs, no more action needed for gfs2-utils.

Comment 13 errata-xmlrpc 2011-02-16 15:07:09 UTC
This issue has been addressed in following products:

  CLuster Suite for RHEL 4

Via RHSA-2011:0264 https://rhn.redhat.com/errata/RHSA-2011-0264.html

Comment 14 errata-xmlrpc 2011-02-16 15:14:46 UTC
This issue has been addressed in following products:

  CLuster Suite for RHEL 4

Via RHSA-2011:0265 https://rhn.redhat.com/errata/RHSA-2011-0265.html


Note You need to log in before you can comment on or make changes to this bug.