Bug 869828 (CVE-2014-2581) - VUL-0: CVE-2014-2581: smb4k: credentials cache leak
Summary: VUL-0: CVE-2014-2581: smb4k: credentials cache leak
Status: RESOLVED WONTFIX
Alias: CVE-2014-2581
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 12.3
: P3 - Medium : Normal
Target Milestone: ---
Assignee: E-mail List
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/97264/
Whiteboard:
Keywords:
Depends on: 869959
Blocks:
  Show dependency treegraph
 
Reported: 2014-03-24 07:49 UTC by Marcus Meissner
Modified: 2017-07-13 11:13 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2014-03-24 07:49:32 UTC
via oss-sec

Date: Mon, 24 Mar 2014 16:19:51 +1100
From: Murray McAllister <mmcallis@redhat.com>
Subject: [oss-security] possible CVE request: smb4k credentials cache leak

Hi,

https://bugs.gentoo.org/show_bug.cgi?id=505376 notes that smb4k (an 
SMB/CIFS share browser for KDE) version 1.1.1 fixes a potential security 
issue:

"Fixed potential security issue reported by Heiner Markert. Do not allow 
the cruid option to be entered via the "Additional options" line edit. 
Also, implement a check in Smb4KMountJob::createMountAction() that 
removes the cruid option from the custom options returned by 
Smb4KSettings::customCIFSOptions()."

http://sourceforge.net/projects/smb4k/files/Smb4K%20%28stable%20releases%29/1.1.1/

Does it need a CVE? I do not have further details, sorry.

--
Murray McAllister / Red Hat Security Response Team

https://bugzilla.redhat.com/show_bug.cgi?id=1079819
Comment 1 Swamp Workflow Management 2014-03-24 23:00:17 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2014-03-26 12:51:35 UTC
CVE-2014-2581 was assigned by Mitre
Comment 3 Johannes Segitz 2015-04-01 12:50:06 UTC
still open for openSUSE
Comment 4 Forgotten User sM9JzehKpy 2015-04-01 15:03:29 UTC
I am very sorry, but this bug will not be fixed until smb4k is ported to KF5.  The submission of newer version of smb4k is depending on bnc#869969, but Sebastian does not agree with the underlying usage/structure of KAuth. As that this will not be changed for the KDE4 network, we can not move forward nor backward. 

At least newer versions for smb4k are being offered through KDE:Extra for the users, but due to the rpmlint errors we can not move it to Factory/Tumbleweed/Maintenance
Comment 5 Johannes Segitz 2015-04-02 07:16:19 UTC
(In reply to Raymond Wooninck from comment #4)
Thanks for the explanation, then we have to wait for now. Users looking here for a fix have your suggestion to use, that's good enough for now
Comment 6 Johannes Segitz 2017-07-13 11:13:08 UTC
fixed in current Leap