Re: Temporary File Creation Bug

Hubert Chan <[email protected]> Wed, 30 Mar 2005 14:30:34 -0500
Newsgroups gmane.linux.cluster.openmosix.mosixview
Message-ID <84e5a6e0ca1f0e1c41b8a91e461d2fd9@evinrude>
Cc-ing Rexotec, since they are the ones who discovered this.

Looking at the original message [1], I think this has all been fixed in
my patches [2] (20-logdirectory.diff and 50-nonodestmp.diff).  At 
least,
my patches:
   - move the openmosixcollector files to /var/lib/openmosixcollector,
     which can be made to be writable only by root
   - don't use /tmp/nodes.tmp

Can someone from Rexotec confirm that this fixes the issue?

*smacking myself for not noticing earlier that this was a security 
issue*

[1] http://www.securityfocus.com/archive/1/394282
[2] http://uw-dig.uwaterloo.ca/~hy3chan/patches/openmosixview/1.5/

Niels do Vos wrote:
> For the users of openMosixView:
>        The vulnerability is not very severe. No need to stress, 
> disable
>        openMosixView or anything like that. Only local users _could_
>        exploid this bug. As long as your users of the cluster behave,
>        you're not in trouble. 

Don't trust your local users.

-- 
Hubert Chan <[email protected]> - http://www.uhoreg.ca/
PGP/GnuPG key: 1024D/124B61FA
Fingerprint: 96C5 012F 5F74 A5F7 1FF7  5291 AF29 C719 124B 61FA
Key available at wwwkeys.pgp.net.   Encrypted e-mail preferred.


-------------------------------------------------------
This SF.net email is sponsored by Demarc:
A global provider of Threat Management Solutions.
Download our HomeAdmin security software for free today!
http://www.demarc.com/info/Sentarus/hamr30