Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2017-7572: backintime: usage of deprecated unix-process polkit authorization subject opens a race condition during authorization | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Matthias Gerstner <matthias.gerstner> |
Component: | Security | Assignee: | Tejas Guruswamy <masterpatricko> |
Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | bwiedemann, hrvoje.senjan, lnussel, matthias.gerstner, meissner |
Version: | Leap 42.2 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
Whiteboard: | |||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Matthias Gerstner
2017-04-06 13:02:27 UTC
This issue was found in the context of a general security review for backintime in bug 1007723. While this issue on its own is not of high severity the following circumstances call for quick action: - There are more minor and moderate issues like a possible DoS in the DBus service. I've created an upstream pull request addressing multiple issues: https://github.com/bit-team/backintime/pull/727. Updates should be submitted that contains all these fixes plus the patch from attachment 719151 [details]. - Affected versions of backintime are currently in Factory, Leap 42.1 and Leap 42.2. All these versions contain the DBus service that was never approved by the security team. This was possible by suppressing the corresponding warnings in the package's rpmlintrc. Please submit fixed versions for Factory, Leap 42.1 and Leap 42.2! The security fix, further hardening and packaging changes have been backported (to the best of my ability) to backintime 1.1.20, the current upstream release. Updated package is now in obs://Archiving:Backup/backintime. Maintenance requests for 42.1 and 42.2 (https://build.opensuse.org/request/show/489654) have been submitted based on this package (so a version update 1.1.6 -> 1.1.20) as the security patches did not apply easily to the earlier versions. Only the Factory update is waiting. Which comes first, the dbus service being added to the whitelist or a Factory submitrequest? I am somewhat puzzled as to how this package was accepted into Factory in the first place, perhaps the submission predated the auto review of rpmlintrc's. This bug (1007723) was mentioned in https://build.opensuse.org/request/show/489654 42.1+42.2 / backintime (In reply to masterpatricko@gmail.com from comment #2) > Updated package is now in obs://Archiving:Backup/backintime. Thank you for your effort. Looks good! > Which comes first, the dbus service being added to the whitelist or a > Factory submitrequest? I will submit the whitelisting to factory, once the #sr is there you can submit your package, too. Both submits can then be handled in the same Factory staging project. I will give you an update when you can do this. > perhaps the submission predated the auto review of rpmlintrc's. We've informed the review team of the situation and they want to investigate on this issue. It's probably some loophole or regression in the checker logic. openSUSE-SU-2017:1124-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1007723,1032717 CVE References: CVE-2017-7572 Sources used: openSUSE Leap 42.2 (src): backintime-1.1.20-3.3.1 openSUSE Leap 42.1 (src): backintime-1.1.20-3.1 This is an autogenerated message for OBS integration: This bug (1032717) was mentioned in https://build.opensuse.org/request/show/491831 Factory / rpmlint This is an autogenerated message for OBS integration: This bug (1032717) was mentioned in https://build.opensuse.org/request/show/492617 Factory / polkit-default-privs The whitelisting is now in factory. Please submit backtintime to Factory. Thank you. Request 495451 has been accepted into Factory. Thanks all. The request which allowed an rpmlintrc into factory was https://build.opensuse.org/request/show/333210, btw: an automatic submission which does not appear to have been reviewed by the usual bots. SUSE-RU-2017:2341-1: An update that has 19 recommended fixes can now be installed. Category: recommended (low) Bug References: 1004346,1007053,1007723,1019748,1032649,1032717,1033296,1033554,1034309,1039290,1039709,1039848,1049694,846337,917781,984817,987141,996111,997880 CVE References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): rpmlint-1.5-41.3.1, rpmlint-mini-1.8-2.2.3 |