Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book General > General Discussions

Notices

Closed Thread
 
Thread Tools Search this Thread
Old 11-03-2011, 06:36 PM   #1
splat
Zealot
splat has a complete set of Star Wars action figures.splat has a complete set of Star Wars action figures.splat has a complete set of Star Wars action figures.splat has a complete set of Star Wars action figures.
 
Posts: 106
Karma: 348
Join Date: Dec 2006
Security bug in Calibre

(Sorry for the cross post but felt this was important enough to get a bit of a wider audience.)

For anyone who takes system security seriously please be aware of a local root exploit for current version of calibre

Proof of concept exploit:
http://www.exploit-db.com/exploits/18071/

Details
https://bugs.launchpad.net/calibre/+bug/885027

Everyone should make sure they update their software as soon as an update with patches is released.
splat is offline  
Old 11-03-2011, 07:01 PM   #2
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,505
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
Vendettas are so ugly.
DiapDealer is offline  
Advert
Old 11-03-2011, 07:05 PM   #3
Bilbo1967
Not scared!
Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.Bilbo1967 ought to be getting tired of karma fortunes by now.
 
Bilbo1967's Avatar
 
Posts: 13,424
Karma: 81011643
Join Date: Mar 2009
Location: Midlands, UK
Device: Kindle Paperwhite 10, Huawei M5 10
Quote:
Originally Posted by DiapDealer View Post
Vendettas are so ugly.
That may be true, but a real refutation would help both me and any future users of Caliber who happen along here.
Bilbo1967 is offline  
Old 11-03-2011, 07:18 PM   #4
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,505
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
Quote:
Originally Posted by Bilbo1967 View Post
That may be true, but a real refutation would help both me and any future users of Caliber who happen along here.
A "real" refutation is a pipe-dream. It's a moving target. Read the bug report and its subsequent comments and make an informed decision on whether the vulnerabilities are something you need to get worked up over as an end-user... or whether they represent the efforts of an overzealous "security expert" who's going to find an exploit in every single application they choose to target.
DiapDealer is offline  
Old 11-03-2011, 07:42 PM   #5
JoeD
Guru
JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.JoeD ought to be getting tired of karma fortunes by now.
 
Posts: 895
Karma: 4383958
Join Date: Nov 2007
Device: na
Why does calibre need to handle mounting in the first place? Do the various linux distro's not already provide a way to mount usb disks? Been a while since i used linux but I remember it been pretty much automated for any removable drive to be mounted.

Having not used calibre on linux though, I may be missing a key point in the arguement
JoeD is offline  
Advert
Old 11-03-2011, 07:42 PM   #6
Serpentine
Evangelist
Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.Serpentine ought to be getting tired of karma fortunes by now.
 
Posts: 416
Karma: 1045911
Join Date: Sep 2011
Location: Cape Town, South Africa
Device: Kindle 3
I love the registration date of some of the users in that thread, how odd!
Serpentine is offline  
Old 11-03-2011, 07:52 PM   #7
jgaiser
Omnivorous
jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.
 
jgaiser's Avatar
 
Posts: 3,283
Karma: 27978909
Join Date: Feb 2008
Location: Rural NW Oregon
Device: Kindle Voyage, Kindle Fire HD, Kindle 3, KPW1
Non-issue. Local exploit only.
jgaiser is offline  
Old 11-03-2011, 08:48 PM   #8
elcreative
Wizard
elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.elcreative ought to be getting tired of karma fortunes by now.
 
Posts: 2,888
Karma: 5875940
Join Date: Dec 2007
Device: PRS505, 600, 350, 650, Nexus 7, Note III, iPad 4 etc
Really dangerous... considering that most calibre users are personal users and don't allow the world and casual passers-by, to have access to their computers physically and should be using decent firewall/security software when net connected... plus I wonder how many people actually keep calibre running 24hours a day, personally I only open it when I'm actually using it!
elcreative is offline  
Old 11-03-2011, 09:16 PM   #9
jgaiser
Omnivorous
jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.jgaiser ought to be getting tired of karma fortunes by now.
 
jgaiser's Avatar
 
Posts: 3,283
Karma: 27978909
Join Date: Feb 2008
Location: Rural NW Oregon
Device: Kindle Voyage, Kindle Fire HD, Kindle 3, KPW1
Local exploits are pretty meaningless to 99% (I don't dare say 100%) of home Linux users. If I have physical access to your machine and the drives are not encrypted, that machine is mine. It's as simple as a flash drive with a live linux distribution. I'm not going to get worked up over a possible local security problem in Calibre.
jgaiser is offline  
Old 11-03-2011, 09:20 PM   #10
Baldrake
Connoisseur
Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.Baldrake once ate a cherry pie in a record 7 seconds.
 
Posts: 90
Karma: 1792
Join Date: Mar 2009
Device: Kindle 3, HTC Mozart
Removed -previous poster said it better...
Baldrake is offline  
Old 11-03-2011, 11:04 PM   #11
Fbone
Is that a sandwich?
Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.Fbone ought to be getting tired of karma fortunes by now.
 
Posts: 8,286
Karma: 101696762
Join Date: Jun 2010
Device: Nook Glowlight Plus
For once Windows users can ignore this security concern.
Fbone is offline  
Old 11-04-2011, 03:54 AM   #12
abookreader
Wizard
abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.abookreader ought to be getting tired of karma fortunes by now.
 
abookreader's Avatar
 
Posts: 1,516
Karma: 2567610
Join Date: Oct 2009
Device: Kindles - Keyboard, Fire, 2-US, iPhone, iPAD
Quote:
Originally Posted by jgaiser View Post
Local exploits are pretty meaningless to 99% (I don't dare say 100%) of home Linux users. If I have physical access to your machine and the drives are not encrypted, that machine is mine. It's as simple as a flash drive with a live linux distribution. I'm not going to get worked up over a possible local security problem in Calibre.
If you get physical access to my machine I guess that pretty much means you've stolen it anyway. You probably have my tv too.
abookreader is offline  
Old 11-04-2011, 07:24 AM   #13
splat
Zealot
splat has a complete set of Star Wars action figures.splat has a complete set of Star Wars action figures.splat has a complete set of Star Wars action figures.splat has a complete set of Star Wars action figures.
 
Posts: 106
Karma: 348
Join Date: Dec 2006
Quote:
Originally Posted by DiapDealer View Post
an overzealous "security expert" who's going to find an exploit in every single application they choose to target.
Do you really not see finding flaws in applications as a problem?

These guys are trying to help and unfortunately the impression I get from Kovid is that it's bare minimum to fix the issue is being done, which results in it being easily worked around time and time again.

There's no dishonour in asking for help if you don't understand something, attacking someone trying to help you is just arrogant (yes I'm aware some of the other posters in the bug report are being d**ks too).

Heck he was given suggestions of using various other more secure apps rather than his own homegrown code. His reply boiled down to, it's not installed on my gentoo box so no. Even when a lead developer for Gentoo comes on and says it's gentoo's issue to fix dependency issues it's a no go.

The mind boggles.
splat is offline  
Old 11-04-2011, 07:46 AM   #14
Rob Lister
Fanatic
Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.Rob Lister ought to be getting tired of karma fortunes by now.
 
Posts: 532
Karma: 3293888
Join Date: Oct 2011
Location: Virginia
Device: Nook Simple Touch
Quote:
Originally Posted by abookreader View Post
If you get physical access to my machine I guess that pretty much means you've stolen it anyway. You probably have my tv too.
Rob Lister is offline  
Old 11-04-2011, 07:58 AM   #15
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,505
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
Quote:
Originally Posted by splat
Do you really not see finding flaws in applications as a problem?
Yes, I definitely see finding flaws in applications as a problem. I find fault with people who make full-time careers out of ferreting out said flaws in free software. Especially the ones who start internet vendettas when the developer(s) of said free software don't immediately jump to "correct" what the "expert" sees as "flaws." It's a form of extortion that I find disgusting.

It's open source... if you can't live with the minor security risk it represents (and it is minor as hell)... patch your own copy to fix the potential hole, or stop using the software. It's that simple.

Quote:
These guys are trying to help and unfortunately the impression I get from Kovid is that it's bare minimum to fix the issue is being done, which results in it being easily worked around time and time again.
These guys aren't trying to "help." Calibre just happened to be the latest target in their sights. I've seen the tactic used again and again and again with various open-source projects. If it's popular, these rats will eventually come out of their holes at some point and attempt to tear it down. "'Fix' it or we'll start an internet-wide smear campaign."

I actually applaud calibre's developers for not giving in to this kind of extortion.

Last edited by DiapDealer; 11-04-2011 at 08:02 AM.
DiapDealer is offline  
Closed Thread


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Calibre bug? pedz Calibre 1 04-02-2010 11:48 PM
Calibre exe deleted by Norton Internet Security 2010 FoolforBooks Calibre 18 11-24-2009 03:10 PM
Calibre 0.4.73 Bug? JuristDoctor Calibre 12 06-24-2008 03:09 PM
Leo Laporte/Security Now Notice the Charging Bug flumbo Sony Reader 2 04-28-2007 11:51 PM


All times are GMT -4. The time now is 07:40 PM.


MobileRead.com is a privately owned, operated and funded community.