![]() |
#1 |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
Security bug in Calibre
(Sorry for the cross post but felt this was important enough to get a bit of a wider audience.)
For anyone who takes system security seriously please be aware of a local root exploit for current version of calibre Proof of concept exploit: http://www.exploit-db.com/exploits/18071/ Details https://bugs.launchpad.net/calibre/+bug/885027 Everyone should make sure they update their software as soon as an update with patches is released. |
![]() |
![]() |
#2 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,505
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
Vendettas are so ugly.
|
![]() |
Advert | |
|
![]() |
#3 |
Not scared!
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 13,424
Karma: 81011643
Join Date: Mar 2009
Location: Midlands, UK
Device: Kindle Paperwhite 10, Huawei M5 10
|
|
![]() |
![]() |
#4 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,505
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
A "real" refutation is a pipe-dream. It's a moving target. Read the bug report and its subsequent comments and make an informed decision on whether the vulnerabilities are something you need to get worked up over as an end-user... or whether they represent the efforts of an overzealous "security expert" who's going to find an exploit in every single application they choose to target.
|
![]() |
![]() |
#5 |
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 895
Karma: 4383958
Join Date: Nov 2007
Device: na
|
Why does calibre need to handle mounting in the first place? Do the various linux distro's not already provide a way to mount usb disks? Been a while since i used linux but I remember it been pretty much automated for any removable drive to be mounted.
Having not used calibre on linux though, I may be missing a key point in the arguement ![]() |
![]() |
Advert | |
|
![]() |
#6 |
Evangelist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 416
Karma: 1045911
Join Date: Sep 2011
Location: Cape Town, South Africa
Device: Kindle 3
|
I love the registration date of some of the users in that thread, how odd!
![]() |
![]() |
![]() |
#7 |
Omnivorous
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,283
Karma: 27978909
Join Date: Feb 2008
Location: Rural NW Oregon
Device: Kindle Voyage, Kindle Fire HD, Kindle 3, KPW1
|
Non-issue. Local exploit only.
|
![]() |
![]() |
#8 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,888
Karma: 5875940
Join Date: Dec 2007
Device: PRS505, 600, 350, 650, Nexus 7, Note III, iPad 4 etc
|
Really dangerous... considering that most calibre users are personal users and don't allow the world and casual passers-by, to have access to their computers physically and should be using decent firewall/security software when net connected... plus I wonder how many people actually keep calibre running 24hours a day, personally I only open it when I'm actually using it!
|
![]() |
![]() |
#9 |
Omnivorous
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,283
Karma: 27978909
Join Date: Feb 2008
Location: Rural NW Oregon
Device: Kindle Voyage, Kindle Fire HD, Kindle 3, KPW1
|
Local exploits are pretty meaningless to 99% (I don't dare say 100%) of home Linux users. If I have physical access to your machine and the drives are not encrypted, that machine is mine. It's as simple as a flash drive with a live linux distribution. I'm not going to get worked up over a possible local security problem in Calibre.
|
![]() |
![]() |
#10 |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 90
Karma: 1792
Join Date: Mar 2009
Device: Kindle 3, HTC Mozart
|
Removed -previous poster said it better...
|
![]() |
![]() |
#11 |
Is that a sandwich?
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 8,286
Karma: 101696762
Join Date: Jun 2010
Device: Nook Glowlight Plus
|
For once Windows users can ignore this security concern.
|
![]() |
![]() |
#12 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,516
Karma: 2567610
Join Date: Oct 2009
Device: Kindles - Keyboard, Fire, 2-US, iPhone, iPAD
|
Quote:
|
|
![]() |
![]() |
#13 | |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
Quote:
These guys are trying to help and unfortunately the impression I get from Kovid is that it's bare minimum to fix the issue is being done, which results in it being easily worked around time and time again. There's no dishonour in asking for help if you don't understand something, attacking someone trying to help you is just arrogant (yes I'm aware some of the other posters in the bug report are being d**ks too). Heck he was given suggestions of using various other more secure apps rather than his own homegrown code. His reply boiled down to, it's not installed on my gentoo box so no. Even when a lead developer for Gentoo comes on and says it's gentoo's issue to fix dependency issues it's a no go. The mind boggles. |
|
![]() |
![]() |
#14 |
Fanatic
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 532
Karma: 3293888
Join Date: Oct 2011
Location: Virginia
Device: Nook Simple Touch
|
|
![]() |
![]() |
#15 | ||
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,505
Karma: 204127028
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
Quote:
It's open source... if you can't live with the minor security risk it represents (and it is minor as hell)... patch your own copy to fix the potential hole, or stop using the software. It's that simple. Quote:
I actually applaud calibre's developers for not giving in to this kind of extortion. Last edited by DiapDealer; 11-04-2011 at 08:02 AM. |
||
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Calibre bug? | pedz | Calibre | 1 | 04-02-2010 11:48 PM |
Calibre exe deleted by Norton Internet Security 2010 | FoolforBooks | Calibre | 18 | 11-24-2009 03:10 PM |
Calibre 0.4.73 Bug? | JuristDoctor | Calibre | 12 | 06-24-2008 03:09 PM |
Leo Laporte/Security Now Notice the Charging Bug | flumbo | Sony Reader | 2 | 04-28-2007 11:51 PM |