Bug 14727 - util-linux new security issue CVE-2014-9114
Summary: util-linux new security issue CVE-2014-9114
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/624610/
Whiteboard: advisory MGA4-64-OK mga4-32-ok has_pr...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-12-04 16:56 CET by David Walser
Modified: 2014-12-09 21:13 CET (History)
4 users (show)

See Also:
Source RPM: util-linux-2.24-2.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-12-04 16:56:51 CET
Fedora has issued an advisory on December 1:
https://lists.fedoraproject.org/pipermail/package-announce/2014-December/145188.html

Patched package uploaded for Cauldron.

Updated (to 2.24.2) and patched package uploaded for Mageia 4.

There's more info on the RedHat bug and oss-security thread linked from there:
https://bugzilla.redhat.com/show_bug.cgi?id=1168485

Advisory:
========================

Updated util-linux packages fix security vulnerability:

Sebastian Krahmer reported a command injection flaw in blkid. This could
possibly result in command execution with root privileges (CVE-2014-9114).

The util-linux package has been updated to version 2.24.2 and patched to
fix this issue and other bugs.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9114
ftp://ftp.kernel.org/pub/linux/utils/util-linux/v2.24/v2.24.1-ReleaseNotes
ftp://ftp.kernel.org/pub/linux/utils/util-linux/v2.24/v2.24.2-ReleaseNotes
https://lists.fedoraproject.org/pipermail/package-announce/2014-December/145188.html
========================

Updated packages in core/updates_testing:
========================
util-linux-2.24.2-1.mga4
libblkid1-2.24.2-1.mga4
libblkid-devel-2.24.2-1.mga4
libuuid1-2.24.2-1.mga4
libuuid-devel-2.24.2-1.mga4
uuidd-2.24.2-1.mga4
libmount1-2.24.2-1.mga4
libmount-devel-2.24.2-1.mga4

from util-linux-2.24.2-1.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
David Walser 2014-12-04 20:33:16 CET

URL: (none) => http://lwn.net/Vulnerabilities/624610/

Comment 1 Herman Viaene 2014-12-05 10:21:43 CET
Testing MGA4-64 ob HP Probook 6555b
Installed all packages mentioned above, no problems encountered.
Checked Fedora advisory, this mentions fdisk and login.
Rebooted the system, login is OK.
As root at CLI:
fdisk -v
returns
fdisk from util-linux 2.24.2
and
fdisk -l
returns the correct list of partitions on /dev/sda

CC: (none) => herman.viaene
Whiteboard: (none) => MGA4-64-OK

Comment 2 Thomas Backlund 2014-12-05 10:51:20 CET
Also check if bootup times have changed
(to help check if it's glibc that adds to bootup time as reported in https://bugs.mageia.org/show_bug.cgi?id=14688)

CC: (none) => tmb

Comment 3 Thomas Backlund 2014-12-05 10:52:01 CET
if it's glibc *or* util-linux
Comment 4 Herman Viaene 2014-12-05 11:51:09 CET
It did not exactly time bootup, but nothing particular has been drawing my attention. Certainly not in the range as David reported.
Comment 5 olivier charles 2014-12-06 09:40:52 CET
Testing on Mageia4-64 in VM

Testing packages :
- util-linux-2.24.2-1.mga4.x86_64
- glibc-2.18-9.6.mga4.x86_64

- lib64blkid1-2.24.2-1.mga4.x86_64
- lib64mount1-2.24.2-1.mga4.x86_64
- lib64uuid1-2.24.2-1.mga4.x86_64
- uuidd-2.24.2-1.mga4.x86_64

Didn't notice anything untoward, no change in boot time either.

CC: (none) => olchal

Comment 6 claire robinson 2014-12-08 15:37:30 CET
Testing complete mga4 32

No issues at reboot or fdisk, blkid or mounting smb shares or local partitions.

Whiteboard: MGA4-64-OK => MGA4-64-OK mga4-32-ok has_procedure

Comment 7 claire robinson 2014-12-09 10:26:35 CET
Validating. I'll upload the advisory shortly

Please push to updates

Thanks

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 8 claire robinson 2014-12-09 10:43:37 CET
Advisory uploaded.

Whiteboard: MGA4-64-OK mga4-32-ok has_procedure => advisory MGA4-64-OK mga4-32-ok has_procedure

Comment 9 Mageia Robot 2014-12-09 21:13:40 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2014-0517.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.