Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 215694
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 215694 depends on: Show dependency tree
Bug 215694 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-04-01 13:03 0000
CVE-2008-1568 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1568):
  comix 3.6.4 allows attackers to execute arbitrary commands via a filename
  containing shell metacharacters that are not properly sanitized when
  executing the rar, unrar, or jpegtran programs.

------- Comment #1 From Robert Buchholz 2008-04-01 13:22:56 0000 -------
See also here for an upstream comment:
https://bugzilla.redhat.com/show_bug.cgi?id=430635#c1

Quoting Tomas Hoger:
Additionally, comix seems to use python's tarfile module to extract tar
archives.  This module has known directory traversal issues (CVE-2007-4559),
which were never fixed upstream.  Tar archive with malicious content can be
used
to overwrite arbitrary file writable by user running comix.

------- Comment #2 From Markus Meier 2008-04-02 20:17:26 0000 -------
I grabbed two patches from fedora (
http://cvs.fedora.redhat.com/viewcvs/rpms/comix/F-8/ ) and added
media-gfx/comix-3.6.4-r1 to the tree. This will hopefully fix this problem.

------- Comment #3 From Robert Buchholz 2008-04-04 02:18:15 0000 -------
looks good, thank you.

Arches, please test and mark stable:
=media-gfx/comix-3.6.4-r1
Target keywords : "amd64 ppc release x86"

------- Comment #4 From Christian Faulhammer 2008-04-04 07:13:39 0000 -------
x86 stable

------- Comment #5 From Markus Meier 2008-04-06 13:48:35 0000 -------
amd64 stable

------- Comment #6 From Tobias Scherbaum 2008-04-06 20:21:14 0000 -------
ppc stable

------- Comment #7 From Peter Volkov 2008-04-07 16:28:23 0000 -------
Fixed in release snapshot.

------- Comment #8 From Tobias Heinlein 2008-04-10 14:29:45 0000 -------
GLSA request filed.

------- Comment #9 From Robert Buchholz 2008-04-15 22:54:19 0000 -------
CVE-2008-1796 has been assigned to the tempfile issue, which was fixed with the
other patch.

------- Comment #10 From Pierre-Yves Rofes 2008-04-25 21:13:33 0000 -------
GLSA 200804-29

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug