Bug 843507 (CVE-2013-4391) - VUL-0: CVE-2013-4391 CVE-2013-4392 CVE-2013-4393 CVE-2013-4394: systemd: 4 security issues
Summary: VUL-0: CVE-2013-4391 CVE-2013-4392 CVE-2013-4393 CVE-2013-4394: systemd: 4 se...
Status: RESOLVED FIXED
Alias: CVE-2013-4391
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other SUSE Other
: P1 - Urgent : Normal
Target Milestone: ---
Assignee: systemd maintainers
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-01 13:43 UTC by Marcus Meissner
Modified: 2015-02-18 21:42 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-10-01 13:43:27 UTC
public via oss-sec

(CVEs not yet assigned. If I should split this bug, please tell.)

Hi All,

I would like to request CVE ids for 4 systemd issues.

1. systemd: Integer overflow, leading to heap-based buffer overflow by
processing native messages
https://bugzilla.redhat.com/show_bug.cgi?id=859051

2. systemd: TOCTOU race condition when updating file permissions and
SELinux security contexts
https://bugzilla.redhat.com/show_bug.cgi?id=859060

3. systemd: Possibility of denial of logging service by processing
native messages from file
https://bugzilla.redhat.com/show_bug.cgi?id=859104

4. systemd: Improper sanitization of invalid XKB layouts descriptions
(privilege escalation when custom PolicyKit local authority file used)
https://bugzilla.redhat.com/show_bug.cgi?id=862324

Thanks!


References:
https://bugzilla.redhat.com/show_bug.cgi?id=859051
https://bugzilla.redhat.com/show_bug.cgi?id=859104
https://bugzilla.redhat.com/show_bug.cgi?id=859060
https://bugzilla.redhat.com/show_bug.cgi?id=862324
http://comments.gmane.org/gmane.comp.security.oss.general/11201
Comment 1 Marcus Meissner 2013-10-01 20:19:25 UTC
> 1. systemd: Integer overflow, leading to heap-based buffer overflow
> by processing native messages 
> https://bugzilla.redhat.com/show_bug.cgi?id=859051

Please use CVE-2013-4391 for this issue.

> 2. systemd: TOCTOU race condition when updating file permissions
> and SELinux security contexts 
> https://bugzilla.redhat.com/show_bug.cgi?id=859060

Please use CVE-2013-4392 for this issue.

> 3. systemd: Possibility of denial of logging service by processing 
> native messages from file 
> https://bugzilla.redhat.com/show_bug.cgi?id=859104

Please use CVE-2013-4393 for this issue.

> 4. systemd: Improper sanitization of invalid XKB layouts
> descriptions (privilege escalation when custom PolicyKit local
> authority file used) 
> https://bugzilla.redhat.com/show_bug.cgi?id=862324

Please use CVE-2013-4394 for this issue.
Comment 2 Swamp Workflow Management 2013-10-01 22:00:38 UTC
bugbot adjusting priority
Comment 3 Frederic Crozat 2013-10-02 07:43:58 UTC
for Factory, was fixed with systemd v207 (already in): CVE-2013-4391

the three others have not patches attached in RH bugzilla (and I didn't find anything in upstream git).
Comment 5 Marcus Meissner 2013-10-31 10:58:24 UTC
ping?
Comment 6 Marcus Meissner 2013-11-05 08:31:56 UTC
ping???
Comment 7 Sebastian Krahmer 2013-11-05 09:09:20 UTC
A CVE-2013-4394 fix is in the RH bugzilla meanwhile.

The others still seem to be private to RH.
Comment 9 Frederic Crozat 2013-11-05 10:14:06 UTC
CVE-2013-4394: this patch is old (2012-10-03), it only on systemd pre version v195, so openSUSE 12.2 or before. openSUSE 12.3 and 13.1 are safe. 

I should be able to backport this patch but I'd prefer to do all of this backporting (ie the other CVE) at the same time ;)
Comment 10 Dr. Werner Fink 2013-11-22 10:34:37 UTC
The question rises : Why are those reports not reported and discucced on the official linux security mailing list?  Simply to help al vendors and not only RedHat to fix them at the same time.
Comment 12 Marcus Meissner 2013-11-22 13:03:49 UTC
to answer #c10 ... no one really cared, and it seems except for one likely fixed already
Comment 13 Victor Pereira 2015-02-18 15:26:21 UTC
ping was it already fixed? I dont see this bnc or the CVEs being mentioned in the systemd.changes, on SLE-12 codestream
Comment 14 Dr. Werner Fink 2015-02-18 16:18:35 UTC
(In reply to Victor Pereira from comment #13)

AFAICS and AFAICR those are fixed with systemd-210 and this is the version for SLES-12
Comment 15 Victor Pereira 2015-02-18 21:42:41 UTC
yes, thank you!