Bug 13478 - smb4k new security issue CVE-2014-2581
Summary: smb4k new security issue CVE-2014-2581
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/601139/
Whiteboard: MGA3TOO has_procedure advisory MGA3-3...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-06-03 18:47 CEST by David Walser
Modified: 2014-06-20 21:53 CEST (History)
3 users (show)

See Also:
Source RPM: smb4k-1.0.7-2.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-06-03 18:47:12 CEST
Fedora has issued an advisory on May 12:
https://lists.fedoraproject.org/pipermail/package-announce/2014-June/133901.html

There's more information on the issue in the RedHat bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1079819

The issue was fixed upstream in 1.1.1.

Mageia 3 and Mageia 4 are also affected.

Reproducible: 

Steps to Reproduce:
David Walser 2014-06-03 18:47:23 CEST

CC: (none) => fundawang
Whiteboard: (none) => MGA4TOO, MGA3TOO

Comment 1 David Walser 2014-06-04 23:37:15 CEST
Updated packages uploaded for Mageia 3, Mageia 4, and Cauldron.

Advisory:
========================

Updated smb4k packages fix security vulnerability:

Smb4k before 1.1.1 allows the cruid CIFS mount option to be specified by the
user (CVE-2014-2581).

The smb4k package has been updated to version 1.1.2, which fixes this issue
and also contains several other bug fixes and additions.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2581
http://sourceforge.net/projects/smb4k/files/1.1.0/
http://sourceforge.net/projects/smb4k/files/1.1.1/
http://sourceforge.net/projects/smb4k/files/1.1.2/
https://lists.fedoraproject.org/pipermail/package-announce/2014-June/133901.html
========================

Updated packages in core/updates_testing:
========================
smb4k-1.1.2-1.mga3
libsmb4kcore4-1.1.2-1.mga3
smb4k-devel-1.1.2-1.mga3
smb4k-1.1.2-1.mga4
libsmb4kcore4-1.1.2-1.mga4
smb4k-devel-1.1.2-1.mga4

from SRPMS:
smb4k-1.1.2-1.mga3.src.rpm
smb4k-1.1.2-1.mga4.src.rpm

Version: Cauldron => 4
Assignee: bugsquad => qa-bugs
Whiteboard: MGA4TOO, MGA3TOO => MGA3TOO

Comment 2 David Walser 2014-06-17 18:13:47 CEST
The Mageia 4 update built against the KDE 4.11.5 update in updates_testing and won't work properly with KDE 4.11.4.  Could a sysadmin please remove the KDE 4.11.5 packages as well as this smb4k update from updates_testing so that I can rebuild it?  Thanks.

CC: (none) => sysadmin-bugs
Whiteboard: MGA3TOO => MGA3TOO feedback

Comment 3 Thomas Backlund 2014-06-18 21:46:22 CEST
KDE 4.11.5 nuked

CC: (none) => tmb
Whiteboard: MGA3TOO feedback => MGA3TOO

Comment 4 David Walser 2014-06-18 22:24:21 CEST
(In reply to Thomas Backlund from comment #3)
> KDE 4.11.5 nuked

Thanks.  Could you nuke the current smb4k build that's there as well?
Comment 5 Thomas Backlund 2014-06-18 23:15:03 CEST
smb4k nuked
Comment 6 David Walser 2014-06-18 23:19:52 CEST
Thanks.  Fresh build submitted.  It should be available in an hour (if the build system starts working correctly again).
Comment 7 David Walser 2014-06-19 19:01:32 CEST
Tested successfully Mageia 3 i586 and Mageia 4 i586 in VMWare VMs.  I was able to scan our local network for Windows machines, and double-click on one to see the shares it had, and double-click on one of the shares to mount it.  I was able to access that filesystem normally, and then unmount it.

In this updated version, once you get to a machine to try to see its shares, it can be a bit awkward.  It wants to use kwallet if you double-click it.  If you just select it and hit the Authentication button in the toolbar, then you can just enter the Windows credentials and it works fine.  That's what I did when I tested the updates.

Whiteboard: MGA3TOO => MGA3TOO has_procedure MGA3-32-OK MGA4-32-OK

Comment 8 claire robinson 2014-06-20 12:51:20 CEST
Testing complete mga4 64

Whiteboard: MGA3TOO has_procedure MGA3-32-OK MGA4-32-OK => MGA3TOO has_procedure MGA3-32-OK MGA4-32-OK mga4-64-ok

Comment 9 claire robinson 2014-06-20 13:00:04 CEST
Testing complete mga3 64

Whiteboard: MGA3TOO has_procedure MGA3-32-OK MGA4-32-OK mga4-64-ok => MGA3TOO has_procedure MGA3-32-OK mga3-64-ok MGA4-32-OK mga4-64-ok

Comment 10 claire robinson 2014-06-20 18:24:45 CEST
Validating. Advisory uploaded.

Could sysadmin please push to 3 & 4 updates

Thanks

Keywords: (none) => validated_update
Whiteboard: MGA3TOO has_procedure MGA3-32-OK mga3-64-ok MGA4-32-OK mga4-64-ok => MGA3TOO has_procedure advisory MGA3-32-OK mga3-64-ok MGA4-32-OK mga4-64-ok

Comment 11 Thomas Backlund 2014-06-20 21:53:03 CEST
Update pushed:
http://advisories.mageia.org/MGASA-2014-0271.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.