Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 264575 (CVE-2009-1962) - <media-gfx/xfig-3.2.5b: Insecure Temporary File Creation (CVE-2009-1962)
Summary: <media-gfx/xfig-3.2.5b: Insecure Temporary File Creation (CVE-2009-1962)
Status: RESOLVED FIXED
Alias: CVE-2009-1962
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-04-02 00:00 UTC by Robert Buchholz (RETIRED)
Modified: 2011-01-02 19:25 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
xfig-3.2.5-mkstemp.patch (xfig-3.2.5-mkstemp.patch,11.37 KB, patch)
2009-04-02 00:01 UTC, Robert Buchholz (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-04-02 00:00:02 UTC
On Wednesday 01 April 2009, Nico Golde wrote:
> it has come to our intention that the Debian package of xfig
> fixes some insecure temporary file creations in various
> places in xfig. I attached the patch.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-04-02 00:01:04 UTC
Created attachment 187036 [details, diff]
xfig-3.2.5-mkstemp.patch
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-06-08 15:57:58 UTC
pva, ping
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-06-11 14:28:05 UTC
The patch above is incomplete, see additional analysis by Tomas Hoger (RedHat): https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-1962
Comment 4 Peter Volkov (RETIRED) gentoo-dev 2010-01-14 20:44:33 UTC
Should be fixed in 3.2.5b. And well... Debian slacks even more since hunk for u_print.c is still not there while we have everything in place. I'll try to open bug since I have more to share with Roland who does great job for Debian.
Comment 5 Peter Volkov (RETIRED) gentoo-dev 2010-01-14 20:46:55 UTC
Oh, and about stabilization. Too many changes there so if possible I'd like to postpone it on one week. In any case xfig is better to be stabilized together with media-gfx/transfig-3.2.5c.
Comment 6 Peter Volkov (RETIRED) gentoo-dev 2010-01-22 15:02:14 UTC
Week passed, no bugs opened. Arch teams, please, stabilize:

media-gfx/xfig-3.2.5b
media-gfx/transfig-3.2.5c
Comment 7 Brent Baude (RETIRED) gentoo-dev 2010-01-23 15:04:27 UTC
ppc64 done
Comment 8 Tobias Klausmann (RETIRED) gentoo-dev 2010-01-23 15:15:09 UTC
Stable on alpha.
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2010-01-23 17:24:19 UTC
Stable for HPPA.
Comment 10 Christian Faulhammer (RETIRED) gentoo-dev 2010-01-23 21:47:46 UTC
x86 stable
Comment 11 Raúl Porcel (RETIRED) gentoo-dev 2010-01-24 17:53:02 UTC
ia64/sparc stable
Comment 12 Markus Meier gentoo-dev 2010-01-31 00:18:10 UTC
amd64 stable
Comment 13 Joe Jezak (RETIRED) gentoo-dev 2010-02-10 03:51:36 UTC
Marked ppc stable.
Comment 14 Tim Sammut (RETIRED) gentoo-dev 2010-12-10 07:09:06 UTC
GLSA Vote: No.
Comment 15 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2011-01-02 19:09:21 UTC
GLSA Vote: No.
Comment 16 Tim Sammut (RETIRED) gentoo-dev 2011-01-02 19:25:10 UTC
(In reply to comment #15)
> GLSA Vote: No.
> 

Thank you. Closing noglsa.