Bug 57470 - [SECURITY] port sysutils/cfengine2: remote root exploit
Summary: [SECURITY] port sysutils/cfengine2: remote root exploit
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: freebsd-ports-bugs (Nobody)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-10-01 18:10 UTC by Oliver Eikemeier
Modified: 2003-11-09 19:18 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Oliver Eikemeier 2003-10-01 18:10:15 UTC
cfengine < 2.0.8 seems to be vulnerable to a remote root exploit.

Port sysutils/cfengine2 has version 2.0.3, the port is part of the
upcoming 4.9 release.

The FreeBSD Security Officer Team was notified on September 30th, 2003.

Fix: 

PR 56710 has an update to version 2.0.8p1, which is not vulnerable.

Otherwise the port should be marked forbidden until it is upgraded.
How-To-Repeat: 
Advisories:
  http://www.securityfocus.com/archive/1/339083
  http://packetstormsecurity.nl/0309-advisories/cfengine.txt
  http://www.securityfocus.com/bid/8699/
  http://mail.gnu.org/archive/html/bug-cfengine/2003-08/msg00014.html

Exploit:
  http://www.securityfocus.com/archive/1/339492 (Red Hat)
Comment 1 Kirill Ponomarev freebsd_committer freebsd_triage 2003-10-01 22:02:03 UTC
Responsible Changed
From-To: freebsd-ports-bugs->fanf

Over to maintainer
Comment 2 Oliver Eikemeier 2003-10-02 15:08:13 UTC
The port has been marked as forbidden in 4.9:

  http://www.freebsd.org/cgi/cvsweb.cgi/ports/sysutils/cfengine2/Makefile.diff?r1=1.26&r2=1.27

This PR can be closed.
Comment 3 Kris Kennaway freebsd_committer freebsd_triage 2003-11-03 01:01:35 UTC
Responsible Changed
From-To: fanf->freebsd-ports-bugs

Port maintainer was reset
Comment 4 jeh freebsd_committer freebsd_triage 2003-11-09 19:17:12 UTC
State Changed
From-To: open->closed

Committed, Thanks
Comment 5 jeh freebsd_committer freebsd_triage 2003-11-09 19:17:12 UTC
State Changed
From-To: open->closed

Closed by PR: 56710
Comment 6 jeh freebsd_committer freebsd_triage 2003-11-09 19:17:12 UTC
State Changed
From-To: open->closed

Closed by PR: 56710