X2Go Bug report logs - #336
Don't allow users to override X2Go commands via ~/bin (or similar)

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Tue, 29 Oct 2013 12:41:16 UTC

Severity: important

Tags: pending

Fixed in version 4.0.2.1

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #12 received at control@bugs.x2go.org (full text, mbox, reply):

Received: (at control) by bugs.x2go.org; 29 Oct 2013 13:43:17 +0000
From mike.gabriel@das-netzwerkteam.de  Tue Oct 29 14:43:09 2013
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=unavailable version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir (Postfix) with ESMTPS id 517CD5DA6C;
	Tue, 29 Oct 2013 14:43:09 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id 073241333;
	Tue, 29 Oct 2013 14:43:09 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id F21743BB58;
	Tue, 29 Oct 2013 14:43:08 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id DaPSKxhjsF8S; Tue, 29 Oct 2013 14:43:08 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id CD4D03BB68;
	Tue, 29 Oct 2013 14:43:08 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPSA id A97083BB58;
	Tue, 29 Oct 2013 14:43:08 +0100 (CET)
Received: from m-047.informatik.uni-kiel.de (m-047.informatik.uni-kiel.de
 [134.245.254.47]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP;
 Tue, 29 Oct 2013 13:43:08 +0000
Date: Tue, 29 Oct 2013 13:43:08 +0000
Message-ID: <20131029134308.Horde.gTVHMctGDotcg4yrnU7YKw1@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: 334@bugs.x2go.org
Cc: control@bugs.x2go.org
Subject: Re: [X2Go-Dev] Bug#334: Don't allow users to override X2Go commands
 via ~/bin (or similar)
References: <20131029124106.Horde.xagnkAt_UswgeDkpr-Foog9@mail.das-netzwerkteam.de>
In-Reply-To: <20131029124106.Horde.xagnkAt_UswgeDkpr-Foog9@mail.das-netzwerkteam.de>
User-Agent: Internet Messaging Program (IMP) H5 (6.1.4)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 134.245.254.47
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:23.0) Gecko/20100101
 Firefox/23.0 Iceweasel/23.0
Content-Type: multipart/signed; boundary="=_cN8QfrtZKqO6KBqhYulU2w4";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
clone #334 -1
reassign #334 python-x2go
thanks

Hi all,

On  Di 29 Okt 2013 13:41:06 CET, Mike Gabriel wrote:

> Package: x2goclient
> Severity: important
>
> In X2Go it is currently possible to replace every command in X2Go  
> Server by a command of the same name in ~/bin.
>
> An attacker could use this to infiltrate X2Go Client with arbitrary data.
>
> IMHO, we should make sure, X2Go Client only uses system-wide paths  
> when evoking commands on X2Go Servers.
>
> This, of course, will boycott installing X2Go Server into ~<user>  
> space, but actually, I prefer a safe setup to such custom  
> installation tweaks.
>
> Feedback?!?
>
> Mike

This issue also applies to Python X2Go.

Mike
-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-keys, inline)]
[Message part 3 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Thu Dec 5 09:02:06 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.