oddjob-0.34.5-3.el8

エラータID: AXSA:2021-1235:01

Release date: 
Sunday, January 17, 2021 - 02:37
Subject: 
oddjob-0.34.5-3.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The oddjob packages contain a D-Bus service which performs particular tasks for clients which connect to it and issue requests using the system-wide message bus.

The following packages have been upgraded to a later upstream version: oddjob (0.34.5).

Security Fix(es):

* oddjob: race condition in oddjob_selinux_mkdir function in mkhomedir.c can lead to symlink attack (CVE-2020-10737)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

CVE-2020-10737
A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. oddjob-0.34.5-3.el8.src.rpm
    MD5: 4b1085c140dcb55c97078c5eb955683e
    SHA-256: 4213e88808530bd34e77271b5d13e8293603c21f7e4730c66d74874c9a2897fc
    Size: 475.56 kB

Asianux Server 8 for x86_64
  1. oddjob-0.34.5-3.el8.x86_64.rpm
    MD5: e442a698afd718c68ba896d4eace9057
    SHA-256: 08d26c5d33c3d7a1d9d50c0c9ae34985caeaea9bf392caa3dc4ef4406b69ded5
    Size: 78.88 kB
  2. oddjob-mkhomedir-0.34.5-3.el8.x86_64.rpm
    MD5: 0a9d13baf95950e8048cf69b52b15c7c
    SHA-256: 9fc0333e9a50c0e1cdc9d07fff55e33d20686c56e70c897199f298100283ed77
    Size: 47.68 kB