Bug 789645 (CVE-2012-0843) - CVE-2012-0843 uzbl: world-readable cookie file
Summary: CVE-2012-0843 uzbl: world-readable cookie file
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-0843
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 789647
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-02-11 23:33 UTC by Kurt Seifried
Modified: 2019-09-29 12:50 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-12-11 08:33:39 UTC
Embargoed:


Attachments (Terms of Use)

Description Kurt Seifried 2012-02-11 23:33:18 UTC
A Debian bug report [1] indicated that uzbl would create the cookies storage
file with world readable permissions.  This could allow other local users to
steal cookies if the user had non-default permissions on their home directory
(by default, home directories are mode 0700 but may be 0755 in some cases, like
for Apache user directories).

ls -ld ~/.local/{,share/{,uzbl/{,cookies.txt}}}
drwxr-xr-x 3 user users 4096 Feb  9 23:29 /home/user/.local/
drwxr-xr-x 4 user users 4096 Feb  9 23:29 /home/user/.local/share/
drwxr-xr-x 2 user users 4096 Feb  9 23:29 /home/user/.local/share/uzbl/
-rw-rw-rw- 1 user users  732 Feb  9 23:29 /home/user/.local/share/uzbl/cookies.txt

[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659379

Comment 1 Kurt Seifried 2012-02-11 23:34:15 UTC
Created uzbl tracking bugs for this issue

Affects: fedora-all [bug 789647]

Comment 2 Fedora Update System 2012-03-02 01:31:57 UTC
uzbl-0-0.28.20111001git9576f59f05.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2012-03-06 19:33:01 UTC
uzbl-0-0.26.20110402gite7578e27c.fc15 has been pushed to the Fedora 15 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2012-03-06 19:33:23 UTC
uzbl-0-0.28.20111001git9576f59f05.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.