Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 578267 - (CVE-2010-0825) CVE-2010-0825 emacs, xemacs: Race condition by moving message from user's inbox into user's Rmail file, when movemail setgid enabled
CVE-2010-0825 emacs, xemacs: Race condition by moving message from user's inb...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
https://bugs.launchpad.net/ubuntu/+so...
impact=low,source=vendor-sec,reported...
: Security
Depends On: 578272 578273
Blocks:
  Show dependency treegraph
 
Reported: 2010-03-30 14:09 EDT by Jan Lieskovsky
Modified: 2015-07-31 02:25 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-04-06 14:38:20 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2010-03-30 14:09:49 EDT
Dan Rosenberg found a race condition in the Emacs's Rmail
subsystem, when moving mail from user's inbox into user's
Rmail file. A local attacker could use this flaw to conduct
symlink attacks on the mailbox of the targeted user, leading
to possibility to read or alter mail of the victim.

References:
  [1] https://bugs.launchpad.net/ubuntu/+source/emacs22/+bug/531569
  [2] http://www.ubuntu.com/usn/USN-919-1

Flaw exploitability note:
  In order the above attack scenario to succeed, the Emacs / Xemacs
movemail binary would need to be equipped with the setgid attribute.
This is NOT the case for versions of emacs and xemacs packages,
as shipped within various Red Hat products.
Comment 4 Jan Lieskovsky 2010-03-30 14:23:24 EDT
This issue does NOT affect the versions of the emacs package, as shipped
with Red Hat Enterprise Linux 3, 4, and 5.

The Emacs movemail binary, responsible for moving email messages
from user's inbox into user's Rmail file is NOT equipped with
setgid attribute (which is required for this flaw to succeed) in
the versions of emacs package, as shipped with Red Hat Enterprise
Linux 3, 4, and 5.

--

This issue does NOT affect the versions of the xemacs package, as shipped
with Red Hat Enterprise Linux 3 and 4.

The Xemacs movemail binary, responsible for moving email messages
from user's inbox into user's Rmail file is NOT equipped with
setgid attribute (which is required for this flaw to succeed) in
the versions of xemacs package, as shipped with Red Hat Enterprise
Linux 3 and 4.

--

This issue does NOT affect the versions of the emacs package, as shipped
with Fedora release of 11 and 12.

The Emacs movemail binary, responsible for moving email messages
from user's inbox into user's Rmail file is NOT equipped 
with setgid attribute (which is required for this flaw to succeed) 
in the versions of emacs package, as shipped with Fedora releases
of 11 and 12.

--

This issue does NOT affect the versions of the xemacs package, as shipped
with Fedora release of 11 and 12.

The Xemacs movemail binary, responsible for moving email messages
from user's inbox into user's Rmail file is NOT equipped
with setgid attribute (which is required for this flaw to succeed)
in the versions of the xemacs package, as shipped with Fedora 
releases of 11 and 12.
Comment 10 Fedora Update System 2010-04-01 14:41:31 EDT
emacs-23.1-13.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/emacs-23.1-13.fc11
Comment 11 Fedora Update System 2010-04-01 14:41:40 EDT
emacs-23.1.94-2.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/emacs-23.1.94-2.fc13
Comment 12 Fedora Update System 2010-04-01 14:41:46 EDT
emacs-23.1-21.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/emacs-23.1-21.fc12
Comment 14 Josh Bressers 2010-04-06 14:38:20 EDT
I'm closing this issue as NOTABUG. No versions of emacs have the setgid bit set on the movemail utility. Without this bit set, the flaw does not exist.

See Comment 4 for more details.
Comment 15 Fedora Update System 2010-04-20 09:09:00 EDT
emacs-23.1-13.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 16 Fedora Update System 2010-04-20 09:30:27 EDT
emacs-23.1-21.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.