[CVE] Socket may be blocked by another user

Bug #1703564 reported by Simon Quigley
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
menu-cache (Ubuntu)
Fix Released
Medium
Unassigned
Trusty
Fix Released
Medium
Simon Quigley
Xenial
Fix Released
Medium
Simon Quigley
Zesty
Fix Released
Medium
Simon Quigley

Bug Description

The socket placed in /tmp is predictable and public-writable. Therefore
if one user placed a symlink to another socket instead of socket for
another use then said another user will either be unable to get menu, or
will receive menu of some other user. Upstream released a fix for this
issue:

https://git.lxde.org/gitweb/?p=lxde/menu-cache.git;a=commitdiff;h=56f66684592abf257c4004e6e1fff041c64a12ce

CVE References

Simon Quigley (tsimonq2)
information type: Public → Public Security
Changed in menu-cache (Ubuntu):
assignee: nobody → Simon Quigley (tsimonq2)
status: New → In Progress
Simon Quigley (tsimonq2)
summary: - Socket may be blocked by another user
+ [CVE] Socket may be blocked by another user
Tyler Hicks (tyhicks)
Changed in menu-cache (Ubuntu Trusty):
importance: Undecided → Medium
Changed in menu-cache (Ubuntu Xenial):
importance: Undecided → Medium
Changed in menu-cache (Ubuntu Zesty):
importance: Undecided → Medium
Changed in menu-cache (Ubuntu):
importance: Undecided → Medium
Simon Quigley (tsimonq2)
Changed in menu-cache (Ubuntu Trusty):
assignee: nobody → Simon Quigley (tsimonq2)
Changed in menu-cache (Ubuntu Xenial):
assignee: nobody → Simon Quigley (tsimonq2)
Changed in menu-cache (Ubuntu Zesty):
assignee: nobody → Simon Quigley (tsimonq2)
Changed in menu-cache (Ubuntu):
assignee: Simon Quigley (tsimonq2) → nobody
status: In Progress → Fix Released
Changed in menu-cache (Ubuntu Trusty):
status: New → In Progress
Changed in menu-cache (Ubuntu Xenial):
status: New → Incomplete
status: Incomplete → In Progress
Changed in menu-cache (Ubuntu Zesty):
status: New → In Progress
Revision history for this message
Simon Quigley (tsimonq2) wrote :

Attached is a debdiff for Zesty applicable to 1.0.2-1. I have tested this on a fresh Lubuntu 17.04 install and it works fine.

Revision history for this message
Simon Quigley (tsimonq2) wrote :

Attached is a debdiff for Xenial applicable to 1.0.1-1build1. I have tested this on a fresh Lubuntu 16.04 LTS install and it works fine.

Revision history for this message
Simon Quigley (tsimonq2) wrote :

Attached is a debdiff for Trusty applicable to 0.5.1-1ubuntu1. I have tested this on a fresh Lubuntu 14.04 LTS install and it works fine.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

ACK on the debdiffs. I've uploaded them for building as a security update with the following minor changes in the patch tags:

- used launchpad url instead of url-shortener
- used the correct commit id

I will release them on Monday.
Thanks!

Changed in menu-cache (Ubuntu Trusty):
status: In Progress → Fix Committed
Changed in menu-cache (Ubuntu Xenial):
status: In Progress → Fix Committed
Changed in menu-cache (Ubuntu Zesty):
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package menu-cache - 1.0.1-1ubuntu0.1

---------------
menu-cache (1.0.1-1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: Socket may be blocked by another user (LP: #1703564)
    - fix-CVE-2017-8933.patch
    - CVE-2017-8933

 -- Simon Quigley <email address hidden> Wed, 09 Aug 2017 08:54:28 -0500

Changed in menu-cache (Ubuntu Xenial):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package menu-cache - 1.0.2-1ubuntu0.1

---------------
menu-cache (1.0.2-1ubuntu0.1) zesty-security; urgency=medium

  * SECURITY UPDATE: Socket may be blocked by another user (LP: #1703564)
    - fix-CVE-2017-8933.patch
    - CVE-2017-8933

 -- Simon Quigley <email address hidden> Wed, 09 Aug 2017 08:42:38 -0500

Changed in menu-cache (Ubuntu Zesty):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package menu-cache - 0.5.1-1ubuntu1.1

---------------
menu-cache (0.5.1-1ubuntu1.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Socket may be blocked by another user (LP: #1703564)
    - fix-CVE-2017-8933.patch
    - CVE-2017-8933

 -- Simon Quigley <email address hidden> Wed, 09 Aug 2017 08:59:35 -0500

Changed in menu-cache (Ubuntu Trusty):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.