SuSE issued an advisory for this on June 24 last year: http://lwn.net/Alerts/449415/ The issue was fixed upstream in version 0.4. Fedora has provided an update to this version for Fedora 16 to fix this issue (May 18): http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082072.html Mageia 1 may be affected as well.
CC: (none) => guillomovitch
I just submitted libgssglue-0.4-1.mga2 and libgssglue-0.1-8.1.mga1 in updates_testing. Suggested advisory: This update fixes insecure getenv() usage in libgssglue, which could be used under some circumstances by local attackers do gain root privileges.
Assignee: bugsquad => qa-bugs
Thanks Guillaume. References for the advisory: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2709 http://lists.opensuse.org/opensuse-security-announce/2011-06/msg00013.html http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082072.html
Testing complete on Mageia 1 i586 for the srpm libgssglue-0.1-8.1.mga1.src.rpm For testing, I used a Mageia 1 client under virtual box accessing an nfs share on the host Mageia 1 system. I'll test Mageia 2 i586 shortly.
CC: (none) => davidwhodginsWhiteboard: (none) => mga1-32-OK
Testing complete on Mageia 2 i586 for the srpm libgssglue-0.4-1.mga2.src.rpm Testing using an nfs share on the Mageia 2 host, accessed by the Mageia 1 vb guest, and and nfs share on the vb guest accessed by the host.
Whiteboard: mga1-32-OK => mga1-32-OK, mga2-32-OK
You may forget testing here, as libgssglue is only used with Kerberos support, and this is really painful to setup.
Should the packages be removed from updates testing, and this bug closed as wont fix then?
Whoa, I don't think that's what he meant. I think he was just saying testing normal NFS functionality won't test the library, so unless you want to go through all the pain of setting Kerberos, just make sure the package installs. I've never used NFS with Kerberos before, but I wasn't aware it was that difficult. I'll probably get to find out pretty soon at work actually.
Ok. We still need 64 bit testing on both releases.
libgssglue installs cleanly on MGA1 64 bits. Testing only install per comment #5
CC: (none) => stormiWhiteboard: mga1-32-OK, mga2-32-OK => MGA1TOO, mga1-32-OK, mga2-32-OK, mga1-64-OK
Testing install on MGA2 64 bits: went fine. Validating per comment #5. Update validated for MGA1 and MGA2. See comment #2 for packages and advisory. Thanks!
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugsWhiteboard: MGA1TOO, mga1-32-OK, mga2-32-OK, mga1-64-OK => MGA1TOO, mga1-32-OK, mga2-32-OK, mga1-64-OK, mga2-64-OK
Update pushed: https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0159
Status: NEW => RESOLVEDCC: (none) => tmbResolution: (none) => FIXED