[Bug 641924] New: Please review systemd
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c0 Summary: Please review systemd Classification: openSUSE Product: openSUSE 11.4 Version: Factory Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: aj@novell.com QAContact: qa@suse.de CC: kasievers@novell.com Found By: Product Management Blocker: --- RPMLINT report: =============== systemd.x86_64: W: suse-dbus-unauthorized-service /usr/share/dbus-1/system-services/org.freedesktop.systemd1.service systemd.x86_64: W: suse-dbus-unauthorized-service /etc/dbus-1/system.d/org.freedesktop.systemd1.conf The package installs an unauthorized DBUS service. Please contact security@suse.de for review. systemd.x86_64: W: polkit-unauthorized-privilege org.freedesktop.systemd1.ReplyPassword Please contact security@suse.de for review. This is with current version of the package in the devel project. Could you review and authorize these, please? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c Ludwig Nussel <lnussel@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|Please review systemd |AUDIT-0: systemd -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c1 Sebastian Krahmer <krahmer@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED CC| |security-team@suse.de AssignedTo|security-team@suse.de |krahmer@novell.com --- Comment #1 from Sebastian Krahmer <krahmer@novell.com> 2010-09-27 07:05:01 UTC --- I put it to my queue. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c2 Marcus Meissner <meissner@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |lnussel@novell.com, | |meissner@novell.com --- Comment #2 from Marcus Meissner <meissner@novell.com> 2011-05-05 06:58:37 UTC --- current Base:System/systemd reports the following new issues: RPMLINT report: =============== systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /usr/share/dbus-1/system-services/org.freedesktop.hostname1.service systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /etc/dbus-1/system.d/org.freedesktop.hostname1.conf The package installs a DBUS system service file. If the package is intended for inclusion in any SUSE product please open a bug report to request review of the service by the security team. systemd.x86_64: I: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.hostname1.set-hostname systemd.x86_64: I: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.hostname1.set-static-hostname systemd.x86_64: I: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.hostname1.set-machine-info systemd.x86_64: I: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.systemd1.reply-password systemd.x86_64: I: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.systemd1.bus-access If the package is intended for inclusion in any SUSE product please open a bug report to request review of the package by the security team -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c3 --- Comment #3 from Bernhard Wiedemann <bwiedemann@novell.com> 2011-05-05 14:00:08 CEST --- This is an autogenerated message for OBS integration: This bug (641924) was mentioned in https://build.opensuse.org/request/show/69690 Factory / polkit-default-privs -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c4 --- Comment #4 from Bernhard Wiedemann <bwiedemann@novell.com> 2011-05-05 16:00:12 CEST --- This is an autogenerated message for OBS integration: This bug (641924) was mentioned in https://build.opensuse.org/request/show/69710 Factory / polkit-default-privs -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c Marcus Meissner <meissner@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P2 - High Severity|Normal |Major -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c5 --- Comment #5 from Ludwig Nussel <lnussel@novell.com> 2011-07-14 11:05:45 CEST --- from bug 705677: systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /etc/dbus-1/system.d/org.freedesktop.login1.conf systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /etc/dbus-1/system.d/org.freedesktop.timedate1.conf systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /usr/share/dbus-1/system-services/org.freedesktop.timedate1.service systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /etc/dbus-1/system.d/org.freedesktop.locale1.conf systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /usr/share/dbus-1/system-services/org.freedesktop.locale1.service systemd.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /usr/share/dbus-1/system-services/org.freedesktop.login1.service -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c6 Andreas Jaeger <aj@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |NEEDINFO InfoProvider| |lnussel@novell.com --- Comment #6 from Andreas Jaeger <aj@novell.com> 2011-07-28 08:08:21 UTC --- Ludwig, could you take care of these as well, please? They come with systemd 31 systemd.x86_64: I: polkit-untracked-privilege org.freedesktop.login1.power-off-multiple-sessions (auth_admin_keep:auth_admin_keep:auth_admin_keep) systemd.x86_64: I: polkit-untracked-privilege org.freedesktop.login1.reboot-multiple-sessions (auth_admin_keep:auth_admin_keep:auth_admin_keep) The privilege is not listed in /etc/polkit-default-privs.* which makes it harder for admins to find. If the package is intended for inclusion in any SUSE product please open a bug report to request review of the package by the security team systemd.x86_64: E: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.login1.power-off (auth_admin_keep:auth_admin_keep:yes) systemd.x86_64: E: polkit-unauthorized-privilege (Badness: 10000) org.freedesktop.login1.reboot (auth_admin_keep:auth_admin_keep:yes) The package allows unprivileged users to carry out privileged operations without authentication. This could cause security problems if not done carefully. If the package is intended for inclusion in any SUSE product please open a bug report to request review of the package by the security team -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c7 Andreas Jaeger <aj@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |ASSIGNED InfoProvider|lnussel@novell.com | --- Comment #7 from Andreas Jaeger <aj@novell.com> 2011-08-02 08:37:16 UTC --- Ludwig updated polkit-prefs - thanks! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c8 Frederic Crozat <fcrozat@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |fcrozat@novell.com --- Comment #8 from Frederic Crozat <fcrozat@novell.com> 2011-09-08 12:45:45 UTC --- can we close this bug ? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c9 Cristian Rodríguez <crrodriguez@opensuse.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |RESOLVED CC| |crrodriguez@opensuse.org Resolution| |FIXED --- Comment #9 from Cristian Rodríguez <crrodriguez@opensuse.org> 2011-12-17 12:20:45 CLST --- (In reply to comment #8)
can we close this bug ?
I think so ;) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c10 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED Resolution|FIXED | --- Comment #10 from Marcus Meissner <meissner@suse.com> 2011-12-20 14:11:40 UTC --- No. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=641924 https://bugzilla.novell.com/show_bug.cgi?id=641924#c11 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Component|Security |Security Product|openSUSE 11.4 |openSUSE 12.2 Target Milestone|--- |Factory --- Comment #11 from Marcus Meissner <meissner@suse.com> 2011-12-20 14:13:56 UTC --- we basically need to audit them... you probably noticed that it did not stop inclusion -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com