|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2017-8849: smb4k local root exploit | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Sebastian Krahmer <krahmer> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | astieger, matthias.gerstner, meissner, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | |||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Sebastian Krahmer
2017-04-26 10:22:05 UTC
This is the split off for fixing/removing smb4k. This was sent to security@kde.org and pending an answer/confirmation from them. We do not expect a quick fix to we available, also due to bug 1036244. An initial thought for a maintenance update would be to remove the mount capability from the package while retaining the network browsing functionality. CRD: 2017-05-15 New CRD: 2017-05-10 CVE-2017-8849 I have just submitted maintenance updates for Leap 41.2, 42.2 that will remove the dbus service and policy files, thus disarming the local root exploit for smb4k. mr#495637, mr#495638 QA reproducer: Before installing the update: $ rpm -ql smb4k | fgrep mounthelper. /etc/dbus-1/system.d/net.sourceforge.smb4k.mounthelper.conf /usr/share/dbus-1/system-services/net.sourceforge.smb4k.mounthelper.service /usr/share/polkit-1/actions/net.sourceforge.smb4k.mounthelper.policy After installing the update $ rpm -ql smb4k | fgrep mounthelper. -> no matches This is an autogenerated message for OBS integration: This bug (1036245) was mentioned in https://build.opensuse.org/request/show/495656 42.2 / smb4k released for 42.2 openSUSE-SU-2017:1343-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1036245 CVE References: CVE-2017-8849 Sources used: openSUSE Leap 42.2 (src): smb4k-1.2.1-3.3.1 |