Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 73307

Summary: Galeon can be used as Trojan horse
Product: [Retired] Red Hat Linux Reporter: jfm2
Component: galeonAssignee: Christopher Blizzard <blizzard>
Status: CLOSED NEXTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 9CC: gczarcinski, kmaraas, mitr, thoron, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: i386   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2003-05-05 16:00:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description jfm2 2002-09-02 19:56:28 UTC
Description of Problem:

The script who fires galeon can be used to cheat another user or the 
superuser into running a program from the attacker.  If You look at 
/usr/bin/galeon you wll noticce that it looks if there is a galeon-bin
program in the CURRENT directory and tries to run it.  So by placing
an exceutable called galeon-bin in one of his directories and then having 
another user to fire galeon from that directory then instead of running the 
real galeon the victim wil be running the Trojan with his own access rights.

Version-Release number of selected component (if applicable):

1.2.0

How Reproducible:

100%

Steps to Reproduce:
1. Make a script called galeon-bin, make it executable.  Fire galeon from
that script and watch the script execute.  (My script just prints: "What's
new doc?)
2. 
3. 

Actual Results:


Expected Results:


Additional Information:

Comment 1 Gene Czarcinski 2003-02-10 15:46:30 UTC
I am not sure this is really a security problem but it still exists.

Comment 2 Kjartan Maraas 2003-04-02 23:28:13 UTC
And in RHL9.

Comment 3 Kjartan Maraas 2003-04-03 20:39:21 UTC
This was fixed today in GNOME CVS. module galeon, branch galeon-1-2

Comment 4 Christopher Blizzard 2003-05-05 16:00:44 UTC
This will get fixed with our next release when we pick up the new galeon version.