First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 73545
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Ervin Németh <ervin.nemeth+org.gentoo.bugs@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
mirrorselect-0.87.patch mirrorselect fix patch Ervin Németh 2004-12-06 04:07 0000 4.64 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 73545 depends on: Show dependency tree
Bug 73545 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-12-06 04:03 0000
I wanted to add a new feature to the mirrorselect script, and stumbled to a
security risc.

------- Comment #1 From Ervin Németh 2004-12-06 04:07:22 0000 -------
Created an attachment (id=45372) [edit]
mirrorselect fix

Here is a small patch, containing the fix, and various enhancements:

* SECURITY FIX: when using the "-b" switch, split is creating files in the
temporary directory in an unsecure manner

* SECURITY FIX: make the script exit if "mktemp" fails

* new switch: "-TX" to allow the user to set the network timeout for wget

* clean up temporary files/directories even if mirrorselect is interrupted by
the user

* fixed progress percentage with "-b" switch

* the logic is rewritten how /etc/make.conf is updated: don't touch it until
everything seems to be o.k.

------- Comment #2 From Luke Macken (RETIRED) 2004-12-06 13:00:12 0000 -------
Re-assigning to security.

tools-portage, please verify.

------- Comment #3 From John Mylchreest (RETIRED) 2004-12-06 13:48:17 0000 -------
thanks Ervin.

0.89 is in portage for your pleasure.

------- Comment #4 From Luke Macken (RETIRED) 2004-12-06 13:50:54 0000 -------
GLSA drafted.

Security, please review.

------- Comment #5 From Luke Macken (RETIRED) 2004-12-07 04:49:17 0000 -------
GLSA 200412-05

Thanks Ervin!  Keep up the good work.

First Last Prev Next    No search results available      Search page      Enter new bug