[Bug 1236556] New: VUL-0: CVE-2024-45339: caddy: github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog

https://bugzilla.suse.com/show_bug.cgi?id=1236556 Bug ID: 1236556 Summary: VUL-0: CVE-2024-45339: caddy: github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.5 Hardware: Other URL: https://smash.suse.de/issue/438660/ OS: Other Status: NEW Whiteboard: CVSSv3.1:SUSE:CVE-2024-45339:7.1:(AV:L/AC:L/PR:L/UI:N/ S:U/C:N/I:H/A:H) Severity: Major Priority: P5 - None Component: Security Assignee: alexandre.vicenzi@suse.com Reporter: emanuele.cappello@suse.com QA Contact: security-team@suse.de Blocks: 1236540 Target Milestone: --- Found By: --- Blocker: --- When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-45339 https://www.cve.org/CVERecord?id=CVE-2024-45339 https://github.com/golang/glog/pull/74 https://github.com/golang/glog/pull/74/commits/b8741656e406e66d6992bc2c9575e... https://groups.google.com/g/golang-announce/c/H-Q4ouHWyKs https://owasp.org/www-community/vulnerabilities/Insecure_Temporary_File https://pkg.go.dev/vuln/GO-2025-3372 https://bugzilla.redhat.com/show_bug.cgi?id=2342463 -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1236556 https://bugzilla.suse.com/show_bug.cgi?id=1236556#c1 --- Comment #1 from Emanuele Cappello <emanuele.cappello@suse.com> --- The packages below are or contain embedded packages that are vulnerable to CVE-2024-45339: - openSUSE:Backports:SLE-15-SP6/caddy contains embedded package: github.com/golang/glog (1.1.0) - openSUSE:Backports:SLE-15-SP6:Update/caddy contains embedded package: github.com/golang/glog (1.2.0) - openSUSE:Factory/caddy contains embedded package: github.com/golang/glog (1.2.0) Please consider version bumping or patching the affected dependencies. The listed codestreams are affected. All other codestreams should not be affected, but feel free to double-check. This is a auto-generated message, please reach out to the reporter directly if you think this is incorrect. No bug-owner found for these packages, if the assignation is not correct feel free to re-assign. -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1236556 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1236556 https://bugzilla.suse.com/show_bug.cgi?id=1236556#c2 --- Comment #2 from Alexandre Vicenzi <alexandre.vicenzi@suse.com> --- This CVE will be fixed in 2.10.0, which is currently in beta. -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1236556 https://bugzilla.suse.com/show_bug.cgi?id=1236556#c3 --- Comment #3 from Alexandre Vicenzi <alexandre.vicenzi@suse.com> --- This was fixed in 2.10.0 [1]. Factory has been updated to 2.10.0 [2]. SRs are open for other codestreams. openSUSE:Leap:16.0 - See [3]. openSUSE:Backports:SLE-15-SP7 - See [4]. openSUSE:Backports:SLE-15-SP6:Update - See [5]. [1]: https://github.com/caddyserver/caddy/commit/0d7c63920daecec510202c42816c883f... [2]: https://build.opensuse.org/request/show/1271292 [3]: https://build.opensuse.org/request/show/1272708 [4]: https://build.opensuse.org/request/show/1272707 [5]: https://build.opensuse.org/request/show/1272705 -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com