Bugzilla – Bug 865854
VUL-0: CVE-2014-0004: udisks: udisks2: local code execution
Last modified: 2015-02-19 01:48:13 UTC
CVE-2014-0004 Florian Weimer of the Red Hat Product Security Team found a flaw in the way udisks and udisks2 handled long path names. A malicious, local user could use this flaw to create a specially-crafted directory structure that could lead to arbitrary code execution with the privileges of the udisks daemon (root).
bugbot adjusting priority
No idea where this cme from. Stefan F., I think this belongs into your team?
that said, it just went public Date: Mon, 10 Mar 2014 15:46:04 +0530 From: Huzaifa Sidhpurwala <huzaifas@redhat.com> Subject: [oss-security] udisks and udisks2: stack-based buffer overflow when handling long path names Hi All, Florian Weimer of the Red Hat Product Security Team, found a flaw in the way udisks and udisks2 handled long path names. A malicious, local user could use this flaw to create a specially-crafted directory structure that could lead to arbitrary code execution with the privileges of the udisks daemon (root). This issue has been assigned CVE-2014-0004. References: http://lists.freedesktop.org/archives/devkit-devel/2014-March/001568.html Patches: http://cgit.freedesktop.org/udisks/commit/?h=udisks1&id=ebf61ed8471 http://cgit.freedesktop.org/udisks/commit/?id=244967 Red Hat bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1049703
This is an autogenerated message for OBS integration: This bug (865854) was mentioned in https://build.opensuse.org/request/show/225457 13.1+12.3 / udisks https://build.opensuse.org/request/show/225464 13.1+12.3 / udisks2
looking good. usually you would reassign this bug to security-team now.
This is an autogenerated message for OBS integration: This bug (865854) was mentioned in https://build.opensuse.org/request/show/225955 Factory / udisks
openSUSE-SU-2014:0388-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 865854 CVE References: CVE-2014-0004 Sources used: openSUSE 13.1 (src): udisks2-2.1.1-2.4.1 openSUSE 12.3 (src): udisks2-2.0.0-5.8.1
openSUSE-SU-2014:0389-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 865854 CVE References: CVE-2014-0004 Sources used: openSUSE 13.1 (src): udisks-1.0.4-13.4.1 openSUSE 12.3 (src): udisks-1.0.4-11.4.1
released
openSUSE-SU-2014:0390-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 865854 CVE References: CVE-2014-0004 Sources used: openSUSE 11.4 (src): udisks-1.0.2-3.16.1