VDB
Sign up
HIGH7.0

GHSA-x6ph-r535-3vjw

apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files

Quick fix

GHSA-x6ph-r535-3vjw — chainguard.dev/apko: upgrade to the fixed version with the command below.

go get chainguard.dev/apko@v0.29.5

Details

It was discovered that the ld.so.cache in images generated by apko had file system permissions mode `0666`: ``` bash-5.3# find / -type f -perm -o+w /etc/ld.so.cache ```

This issue was introduced in commit [04f37e2 ("generate /etc/ld.so.cache (#1629)")](https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9)([v0.27.0](https://github.com/chainguard-dev/apko/releases/tag/v0.27.0)).

### Impact This potentially allows a local unprivileged user to add additional additional directories including dynamic libraries to the dynamic loader path. A user could exploit this by placing a malicious library in a directory they control.

### Patches This issue was addressed in apko in [aedb077 ("fix: /etc/ld.so.cache file permissions (#1758)")](https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3) ([v0.29.5](https://github.com/chainguard-dev/apko/releases/tag/v0.29.5)).

### Acknowledgements

Many thanks to Cody Harris from [H2O.ai](http://h2o.ai/) for reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/chainguard.dev/apko
Introduced in: 0.27.0Fixed in: 0.29.5
Fixgo get chainguard.dev/apko@v0.29.5

References