Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
BID:15120
Info
Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
| Bugtraq ID: | 15120 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 17 2005 12:00AM |
| Updated: | Oct 17 2005 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: |
Gentoo sci-libs/gdal 1.3 .0-r1 Gentoo sci-libs/gdal 1.2.6 -r4 Gentoo net-nds/openldap 2.2.8 -r3 Gentoo media-gfx/imagemagick 6.2.4 .2-r1 Gentoo dev-util/cmake 2.2 .0-r1 Gentoo dev-util/cmake 2.0.6 -r1 Gentoo dev-lang/perl 5.8.7 -r1 Gentoo dev-lang/perl 5.8.6 -r6 Gentoo dev-lang/gauche 0.8.6 -r1 Gentoo dev-db/qt-unixodbc 3.3.4 -r1 Gentoo dev-db/qdbm 1.8.33 -r2 |
Discussion
Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
Multiple packages in Gentoo Linux are susceptible to an insecure RUNPATH vulnerability. This issue is due to a flaw in the build system that results in insecure RUNPATHs being included in certain binaries.
This vulnerability may result in arbitrary code being executed in the context of users executing the vulnerable executables. This may facilitate privilege escalation.
This issue is only exploitable by users that are members of the 'portage' group.
Multiple packages in Gentoo Linux are susceptible to an insecure RUNPATH vulnerability. This issue is due to a flaw in the build system that results in insecure RUNPATHs being included in certain binaries.
This vulnerability may result in arbitrary code being executed in the context of users executing the vulnerable executables. This may facilitate privilege escalation.
This issue is only exploitable by users that are members of the 'portage' group.
Exploit / POC
Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
Solution:
Gentoo has released advisory GLSA 200510-14, along with fixes to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
Perl users:
emerge --sync
emerge --ask --oneshot --verbose dev-lang/perl
Qt-UnixODBC users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-db/qt-unixodbc-3.3.4-r1"
CMake users:
emerge --sync
emerge --ask --oneshot --verbose dev-util/cmake
Please see the referenced advisory for further details.
Gentoo has released advisory GLSA 200511-02 to address this issue in further Gentoo packages. Users of affected packages are urged to execute the following commands with superuser privileges:
QDBM users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-db/qdbm-1.8.33-r2"
ImageMagick users:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/imagemagick-6.2.4.2-r1"
GDAL users:
emerge --sync
emerge --ask --oneshot --verbose sci-libs/gdal
Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200512-07 to address this issue in further Gentoo packages. Users of affected packages are urged to execute the following commands with superuser privileges:
All OpenLDAP users:
# emerge --sync
# emerge --ask --oneshot --verbose net-nds/openldap
All Gauche users:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/gauche-0.8.6-r1"
Solution:
Gentoo has released advisory GLSA 200510-14, along with fixes to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
Perl users:
emerge --sync
emerge --ask --oneshot --verbose dev-lang/perl
Qt-UnixODBC users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-db/qt-unixodbc-3.3.4-r1"
CMake users:
emerge --sync
emerge --ask --oneshot --verbose dev-util/cmake
Please see the referenced advisory for further details.
Gentoo has released advisory GLSA 200511-02 to address this issue in further Gentoo packages. Users of affected packages are urged to execute the following commands with superuser privileges:
QDBM users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-db/qdbm-1.8.33-r2"
ImageMagick users:
emerge --sync
emerge --ask --oneshot --verbose ">=media-gfx/imagemagick-6.2.4.2-r1"
GDAL users:
emerge --sync
emerge --ask --oneshot --verbose sci-libs/gdal
Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200512-07 to address this issue in further Gentoo packages. Users of affected packages are urged to execute the following commands with superuser privileges:
All OpenLDAP users:
# emerge --sync
# emerge --ask --oneshot --verbose net-nds/openldap
All Gauche users:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/gauche-0.8.6-r1"
References
Gentoo Linux Multiple Packages Insecure RUNPATH Vulnerability
References:
References:
- CVE-2015-7513 Kernel: kvm: divide by zero issue leads to DoS (Prasad J Pandit)