Your message dated Sun, 5 Apr 2009 00:39:27 +0200
with message-id <[email protected]>
and subject line Re: [Pkg-openldap-devel] Bug#253838: Bug#253838: Security risk 
in libldap
has caused the Debian Bug report #253838,
regarding libldap2 reads from ~/.ldaprc and $PWD/ldaprc while running 
privileged programs
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
253838: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=253838
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libldap2
Version: 2.1.30-1
Severity: normal
Tags: security

This bug is visible in systems with libnss-ldap and libpam-ldap.
Even privileged programs (like su) read configuration file from users
home and current directory (follows symlinks too).

It don't take any settings from that files, but I think it's minor
security issue (DoS possible even with limits enabled for example).

Simple check, try on system where NSS & PAM use LDAP:
$mknod ldaprc p
$su - user
It halts on reading from pipe (rather useless).

Another check:
$ln -s /dev/hda ldaprc
$su - user
and su reads entire hard disk (maybe DoS if many simultanous reads ?).

If exists files with read-triggered action (under /proc or /sys, new
ACPI patches ?[1]), it's possible to unprivileged user to trigger them.

Friend told me that Redhat include patch to disable reading those files when
euid != uid.

Regards,
Rafal Kupka

[1] http://www.kerneltraffic.org/kernel-traffic/kt20040609_261.html#4

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.4.26-grsec-evms
Locale: LANG=C, LC_CTYPE=C (ignored: LC_ALL set to pl_PL)

Versions of packages libldap2 depends on:
ii  libc6                       2.3.2.ds1-13 GNU C Library: Shared libraries an
ii  libgnutls10                 1.0.4-3      GNU TLS library - runtime library
ii  libsasl2                    2.1.18-4.1   Authentication abstraction library

-- no debconf information


--- End Message ---
--- Begin Message ---
Version: 2.4.15-1

On Thu, Nov 20, 2008 at 05:28:37PM -0800, Quanah Gibson-Mount wrote:
> --On Thursday, November 20, 2008 2:49 PM -0800 Quanah Gibson-Mount  
> <[email protected]> wrote:
>
>> --On Thursday, November 20, 2008 11:37 PM +0100 Moritz Muehlenhoff
>> <[email protected]> wrote:
>>
>> I suggest you talk to the OpenLDAP folks before applying this.
>
> ITS#4750 has been fixed in RE24, and will be part of 2.4.13.

Closing with the next version uploaded to the archive, 2.4.15.

Cheers,
        Moritz


--- End Message ---

Reply via email to