Possible wcid vulnrability

Other talk about Salix

Possible wcid vulnrability

Postby toothandnail » 13. Apr 2012, 14:36

Don't know if others have seen this: http://www.theregister.co.uk/2012/04/12 ... inux_0day/

Looks as though wcid may have a problem, though it isn't clear how much of a problem it is. Are there plans to get the patched version into Salix?

Paul.
toothandnail
 
Posts: 165
Joined: 20. Sep 2009, 17:30
Location: Oxfordshire, UK

Re: Possible wcid vulnrability

Postby JRD » 16. Apr 2012, 08:58

Yes it affects Salix. We will release a upgrade of the wicd package very soon.

The patch to apply to your wicd source if you do not want to wait :
http://bugs.debian.org/cgi-bin/bugrepor ... bug=668397
http://bazaar.launchpad.net/~wicd-devel ... vision/751
Image
User avatar
JRD
Salix Warrior
 
Posts: 952
Joined: 7. Jun 2009, 22:52
Location: Lyon, France

Re: Possible wcid vulnrability

Postby Adys » 16. Apr 2012, 14:24

FWIW,

wicd 1.7 launchpad revision 756, latest version is 1.7.2.1. (and some bug report was already filed after that release about slackware64 among others, but it is not yet confirmed).

BTW, for the future 1.7.3,
Code: Select all
https://launchpad.net/wicd/+milestone/1.7.3


The WICD GTK client should be ported to GTK-3 and GObject introspection.
Possibly, it should be made so it supports both versions of GTK.
Adys
 
Posts: 154
Joined: 3. Apr 2012, 04:17

Re: Possible wcid vulnrability

Postby JRD » 16. Apr 2012, 15:05

That's why I said to apply just this patches.
Wicd is in python, so no need to recompile anything, it could be applied easily.
Image
User avatar
JRD
Salix Warrior
 
Posts: 952
Joined: 7. Jun 2009, 22:52
Location: Lyon, France

Re: Possible wcid vulnrability

Postby gapan » 22. Apr 2012, 20:45

Yes, the vulnerability is there. But it's only local, which means someone has to have physical access to your PC in order to exploit it. In addition, the wicd devs haven't really settled on a fix yet. Until now, they have released version 1.7.2 with a fix for this exploit, then released 1.7.2.1 for fixing a utf8 bug in wicd-curses, then released 1.7.2.2 because 1.7.2 and 1.7.2.1 were broken because of the security fix and they just released 1.7.2.3 with the comment in the changelog being "Fix 1.7.2.2 brokenness". All these within 10 days. I wouldn't bet that there won't be yet another fix for further breakage very soon. So between a functioning version with a known local exploit and a broken version without the local exploit, for now I choose the former. We may upgrade if they settle on a fix that doesn't break anything else.
Image
User avatar
gapan
Salix Wizard
 
Posts: 3482
Joined: 6. Jun 2009, 17:40

Re: Possible wcid vulnrability

Postby GJones » 27. Apr 2012, 03:48

Local vulnerabilities can still be serious, IMO. See for instance Stuxnet, which followed up an arbitrary code execution exploit with a local privilege elevation one to root a Windows machine from an infected USB stick. User browses through contents of USB stick, Explorer renders the malicious LNK file and executes the payload -> bam, compromised. Not likely for anything like that to happen on Linux (yet), but I think my point still stands.
GJones
 
Posts: 256
Joined: 22. Jul 2011, 23:27

Re: Possible wcid vulnrability

Postby Shador » 27. Apr 2012, 07:09

Nobodies saying it's not serious. Just a lot less serious than a remote exploit with such possibilities would be. Anyway, if a supposed fix is just creating more problems there's not much use in it.
Image
Shador
Salix Warrior
 
Posts: 1295
Joined: 11. Jun 2009, 14:04
Location: Bavaria

Re: Possible wcid vulnrability

Postby gapan » 27. Apr 2012, 08:00

If you haven't noticed, slackware pushed an upgrade some days ago, to version 1.7.2.1.
Image
User avatar
gapan
Salix Wizard
 
Posts: 3482
Joined: 6. Jun 2009, 17:40


Return to Misc