Bug 1039138 (CVE-2017-8933) - VUL-0: CVE-2017-8933: menu-cache: predictable and public-writable socket placed in /tmp
Summary: VUL-0: CVE-2017-8933: menu-cache: predictable and public-writable socket plac...
Status: RESOLVED FIXED
Alias: CVE-2017-8933
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other All
: P3 - Medium : Normal
Target Milestone: unspecified
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/185304/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-15 15:55 UTC by Mikhail Kasimov
Modified: 2024-05-08 14:24 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mikhail Kasimov 2017-05-15 15:55:18 UTC
Ref: http://seclists.org/oss-sec/2017/q2/260
============================================
The socket placed in /tmp is predictable and public-writable. Therefore
if one user placed a symlink to another socket instead of socket for
another use then said another user will either be unable to get menu, or
will receive menu of some other user.

This bug has been assigned to CVE-2017-8933 [1].  A fix has been
committed to menu-cache's git repository [2].  LXDE developers are
working on a release which fixes the problem.

[1]: https://git.lxde.org/gitweb/?p=lxde/menu-cache.git;a=commitdiff;h=56f66684592abf257c4004e6e1fff041c64a12ce
============================================

(open-)SUSE: https://software.opensuse.org/package/libmenu-cache3

1.0.2 (TW, official)
1.0.0 (42.{1,2}, official)
Comment 1 Andreas Stieger 2017-05-19 09:46:14 UTC
openSUSE only. Source package is menu-cache. Assign to maintainer.
Comment 2 Michael Vetter 2024-03-12 16:04:03 UTC
This is fixed in version 1.1.0 via https://github.com/lxde/menu-cache/commit/56f66684592abf257c4004e6e1fff041c64a12ce.

openSUSE_Backports_SLE-15-SP5_Update and Factory contain 1.1.0.