Title: Gentoo app-backup/burp root privilege escalation via writable config
Author: Michael Orlitzky
Fixed in: Partially addressed in commits 25a4b59e and 5cd39164; fully fixed in commits 4b3a76d6 and 2faf0fcb and version 2.1.32-r1
Summary
Before 2.1.32-r1, Gentoo’s app-backup/burp package gave its daemon runtime group ownership of the configuration directory. The runtime user or another group member could alter configuration that the OpenRC service script later used while running as root, allowing privilege escalation.
Learn more
Michael Orlitzky’s detailed advisory provides the full technical disclosure and remediation references for CVE-2017-18285.
What is CVE?
Common Vulnerabilities and Exposures (CVE) provides standard public identifiers for known cybersecurity vulnerabilities. MITRE maintains the CVE program and coordinates its vulnerability-identification ecosystem in the public interest.
About Metro Data, Inc.
Founded in 1994, Metro Data, Inc. is an information-systems and services firm that works exclusively with business clients to develop and apply technology solutions aligned with client goals.
Metro Data’s end-to-end experience helps customers keep pace with changing technology, secure systems, reduce costs, and improve information-system performance.
About the CVE author, Michael J. Orlitzky
Michael J. Orlitzky is a long-time Metro Data technical leader with a Ph.D. in mathematics who has discovered and helped remediate vulnerabilities in operating systems and application software, with research recognized by industry and academic peers.