Description Galen Thurber 2013-03-10 00:41:28 CET
rkhunter 1.3.8
false positive for gaskit rootkit
due to existance of /dev/dev/

ls -al /dev/dev/
total 0
drwxr-xr-x  2 root root   60 Mar  9 15:21 ./
drwxr-xr-x 20 root root 4080 Mar  9 19:23 ../
lrwxrwxrwx  1 root root   10 Mar  9 15:21 resume -> ../../sda1
Comment 1 Galen Thurber 2013-03-10 00:42:24 CET
rkhunter --update
rkunter --propudp
rkunter -c
Galen Thurber 2013-03-10 01:34:26 CET

Summary: rkhunter false positve for gaskit => rkhunter false positive for gaskit

Comment 2 Remco Rijnders 2013-06-23 16:19:17 CEST
Hi Galen, thank you for your report. I believe this problem has been fixed in rkhunter-1.3.8-3.1.mga2.

@qa: To test this, issue the following three commands:
rkhunter --update
rkhunter --propupd
rkhunter -c

With the version of rkhunter in release, the third command will show that the gaskit rootkit was possibly found. With the updated version in updates_testing, this should no longer be the case.

Advisory text:
Updated rkhunter package eliminates false positive on gaskit rootkit

Using rkhunter on a Mageia 2 system, the gaskit rootkit was erroneously detected as it triggered on the presence of the directory /dev/dev which is commonly available on Mageia systems. This updated package eliminates this false positive.




Comment 3 martyn vidler 2013-06-23 20:13:32 CEST
You have this down for testing in MGA3 There is no /dev/dev in either my 32 or 64 mga3?

Comment 4 Remco Rijnders 2013-06-23 20:34:28 CEST
Hi martyn,

I'm not sure exactly which package creates this directory. But if you have ever put your machine to hibernate / sleep, I expect this directory to be created. If you don't have it on your machine, perhaps you are not the best test subject for this bug report ;-)   I do have this directory on both my Mageia 2 and Cauldron system.
Comment 5 David Walser 2013-06-23 21:05:17 CEST
As this is the bug with the advisory, I'll make the others depend on this one, and assign the others back to you.  Only one bug should be assigned to QA for this update.

Comment 6 David Walser 2013-06-23 21:08:34 CEST
As this bug had MGA3TOO, I'm assuming this is being in the Mageia 3 update as well.

rkhunter-1.4.0-3.1.mga3 should be included in the package list.
Comment 7 Remco Rijnders 2013-06-24 07:14:53 CEST
Thanks luigi!

Updated advisory text to cover all 3 problem reports:

Advisory text:
Updated rkhunter package addresses various issues

Using rkhunter on a Mageia 2 or 3 system, the gaskit rootkit was erroneously detected as it triggered on the presence of the directory /dev/dev which is commonly available on Mageia systems.

Furthermore, the whitelisting of a file which no longer is present on Mageia 3 systems would prevent rkhunter from starting properly. Other files which should have been whitelisted were missing, resulting in warnings appearing.

This update addresses these issues. rkhunter users are advised to install the updated package.



Comment 8 James Kerr 2013-06-24 10:36:44 CEST
Confirmed that the update fixes all three bugs on x86_64, Mageia 3

I executed rkhunter -c
and /etc/cron.daily/rkhunter

each time, rkhunter ran and did not report any warnings.
Comment 9 Rémi Verschelde 2013-06-25 09:11:31 CEST
Testing complete on Mageia 3 i586.

Bug 9313: Did not see any false positive, but with the package in core/release, "rkhunter -c" would just should the error of bug 9398. With the update candidate, the check is performed.

Bug 9398: Could reproduce, and the update fixes it.

Bug 8172: Could not reproduce with rkhunter-1.4.0-3.mga3 from core/release, so I suppose it was fixed between mga3 alpha3 and the release. If yes it should be removed from the advisory.

@James Kerr: Thanks for testing on x86_64, I added MGA3-64-OK to the whiteboard for you.

Comment 10 James Kerr 2013-06-25 10:41:16 CEST
Re bug 8172. /etc/cron.daily/rkhunter  was reporting that warning before the update. See my comment on that bug.
Comment 11 Samuel Verschelde 2013-06-25 12:53:18 CEST
Testing complete on Mageia 2 x86_64 for bug #9313

Comment 12 claire robinson 2013-06-25 13:14:19 CEST
Advisory added to svn
Comment 13 David GEIGER 2013-06-25 15:36:38 CEST
Created attachment 4167 [details]
rkhunter.log file

Testing complete for rkhunter-1.4.0-3.1.mga3 on Mageia release 3 (Official) for x86_64, for me it's Ok no false positive on check.

rkhunter --update
rkhunter --propupd
rkhunter -c

Comment 14 Rémi Verschelde 2013-06-25 17:34:18 CEST
Testing complete on Mageia 2 i586.

Validating update.
Please commit the advisory (comment 7) and push the update.

Comment 15 Nicolas Vigier 2013-06-26 19:57:49 CEST

