|
|
Log in / Subscribe / Register

Gentoo alert 200601-01 (pinentry)

From:  Thierry Carrez <koon@gentoo.org>
To:  gentoo-announce@lists.gentoo.org
Subject:  [gentoo-announce] [ GLSA 200601-01 ] pinentry: Local privilege escalation
Date:  Tue, 03 Jan 2006 15:51:55 +0100
Cc:  bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk, security-alerts@linuxsecurity.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200601-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: pinentry: Local privilege escalation Date: January 03, 2006 Bugs: #116822 ID: 200601-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== pinentry is vulnerable to privilege escalation. Background ========== pinentry is a collection of simple PIN or passphrase entry dialogs which utilize the Assuan protocol. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-crypt/pinentry < 0.7.2-r2 >= 0.7.2-r2 Description =========== Tavis Ormandy of the Gentoo Linux Security Audit Team has discovered that the pinentry ebuild incorrectly sets the permissions of the pinentry binaries upon installation, so that the sgid bit is set making them execute with the privileges of group ID 0. Impact ====== A user of pinentry could potentially read and overwrite files with a group ID of 0. Workaround ========== There is no known workaround at this time. Resolution ========== All pinentry users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-crypt/pinentry-0.7.2-r2" Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200601-01.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. License ======= Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.0


to post comments

Gentoo update to pinentry

Posted Jan 4, 2006 18:31 UTC (Wed) by dd9jn (✭ supporter ✭, #4459) [Link] (1 responses)

That is a strange alert. pinentry is - similar to gpg - designed to be suid(root). It drops priviliges as soon as it has mlock()ed some memory to avoid leakage of passphrases (or well PINs) to the the swap space.

I got no bug report related to pinentry, thus I wonder how they managed to create a privilege escalation.

Gentoo update to pinentry

Posted Jan 4, 2006 19:45 UTC (Wed) by dd9jn (✭ supporter ✭, #4459) [Link]

Sorry, I did not noticed that they are talking about gid 0 and not knowing there build system I was under the impression that chmod u-s .


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds