/etc/sudoers can be destroyed

Bug #74553 reported by Rich Johnson
256
Affects Status Importance Assigned to Milestone
smb4k (Ubuntu)
Invalid
Undecided
Unassigned
Edgy
Won't Fix
Low
Unassigned

Bug Description

Binary package hint: smb4k

smb4k has a bug in the 0.7 releases that allows the application to change the /etc/sudoers file.

Upstream Bug:
http://developer.berlios.de/bugs/?func=detailbug&bug_id=9527&group_id=769

Package in Debian includes:
 * New upstream release
   This version fixes a grave security bug present in all 0.7 versions with
   sudoers file management.

Debian changelog:
http://packages.debian.org/changelogs/pool/main/s/smb4k/smb4k_0.7.5-1/changelog

Revision history for this message
Rich Johnson (nixternal) wrote :
Revision history for this message
Kees Cook (kees) wrote :

Thanks for putting this together!

This debdiff looks like a full diff between 0.7.1 and 0.7.5. For doing security updates, we only do minimal security patches, which should be limited to the specific problem with version 0.7.1. If you can extract, backport to 0.7.1, build, and test the fixes, then we can go from that debdiff. Since edgy is stable, we can't be doing large code changes to it, unfortunately. :(

Would you be able to isolate the specific patch that fixes the problem and give it some testing?

Revision history for this message
Rich Johnson (nixternal) wrote :

Hey Kees,

Just checking the status on this bug for Edgy? Dapper is supposedly fine as this issue only happened with the .7.x releases. Thanks again for the help.

Revision history for this message
Kees Cook (kees) wrote :

Basically, this is on hold until someone can produce a debdiff that contains only the security fixes. Also, since this bug is really only a problem for people that can already "su", so it's pretty low priority as I understand it.

Changed in smb4k:
importance: Undecided → Low
status: Unconfirmed → Confirmed
Revision history for this message
Kees Cook (kees) wrote :

Rejecting devel task, marking as an Edgy task.

Changed in smb4k:
importance: Undecided → Low
status: Unconfirmed → Confirmed
importance: Low → Undecided
status: Confirmed → Rejected
Revision history for this message
William Grant (wgrant) wrote :

Edgy is EOL.

Changed in smb4k:
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.