Description: A flaw was found in the metadata constraints in gluster-swift package. By adding metadata in several separate calls, a malicious user could bypass the maxmetacount constraint, and store more metadata than allowed by the configuration.
References: http://seclists.org/oss-sec/2015/q3/448 https://review.openstack.org/#/c/215487
Following the fixing of several /tmp/ flaws in CVE-2012-4417 we have the remaining issues in Gluster reported by Kurt Seifried (kseifried):
============== This issue was previously not reported: This should probably use /var/run/gluster/glusterdump.%d.options
tests/volume.rc: rm -f /tmp/glusterdump.$mountpid.dump. 2>/dev/null tests/volume.rc: fname=$(ls /tmp | grep -E "glusterdump.$mountpid.dump.") tests/volume.rc: echo /tmp/$fname ============== ============== This issue was previously not reported: This should use mktemp Also this should use cp instead of mv so you don't lose SELinux context when copying the file back to /etc/samba/smb.conf which might break Samba
extras/hook-scripts/S30samba-stop.sh: cp /etc/samba/smb.conf /tmp/smb.conf extras/hook-scripts/S30samba-stop.sh: sed -i "/gluster-$volname/,/^$/d" /tmp/smb.conf &&\ extras/hook-scripts/S30samba-stop.sh: mv /tmp/smb.conf /etc/samba/smb.conf ==============
============== This issue was previously reported: This should use mkstemp()
libglusterfs/src/run.c: fd = open ("/tmp/foof", OWRONLY|OCREAT|OTRUNC, 0600); ==============
============== This issue was previously reported: This should probably use /var/run/gluster/glusterdump.%d.options
libglusterfs/src/statedump.c:/ These options are dumped by default if /tmp/glusterdump.options libglusterfs/src/statedump.c: / glusterd will create a file /tmp/glusterdump.<pid>.options and libglusterfs/src/statedump.c: both cli command and SIGUSR1, /tmp/glusterdump.options file libglusterfs/src/statedump.c: "/tmp/glusterdump.options"); libglusterfs/src/statedump.c: "/tmp/glusterdump.%d.options", getpid ()); libglusterfs/src/statedump.c: ((ctx->statedumppath != NULL)?ctx->statedumppath:"/tmp")), ==============
============== This issue was previously reported: This should probably use /var/run/gluster/glusterdump.%d.options
xlators/protocol/server/src/server.c: .defaultvalue = "/tmp", xlators/protocol/server/src/server.c: " statedumps. By default it is the /tmp directory" ============== ============== This issue was previously reported: This should probably use /var/run/gluster/%s-"RBCLIENTMOUNTPOINT
xlators/mgmt/glusterd/src/glusterd-replace-brick.c: snprintf (path, len, "/tmp/%s-"RBCLIENTMOUNTPOINT, volinfo->volname); ==============
============== This issue was previously reported: This should probably use /var/run/gluster/glusterdump.%d.options
xlators/mgmt/glusterd/src/glusterd-utils.c: snprintf (dumpoptionspath, sizeof (dumpoptionspath), "/tmp/glusterdump.%d.options", pid); xlators/mgmt/glusterd/src/glusterd-utils.c: snprintf (dumpoptionspath, sizeof (dumpoptionspath), "/tmp/glusterdump.%d.options", pid); ==============