Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 99173 - net-im/skype Insecure temp file creation
Summary: net-im/skype Insecure temp file creation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://archives.neohapsis.com/archive...
Whiteboard: ~3 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-07-16 00:37 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-07-31 13:33 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-16 00:37:25 UTC
Summary (full details in URL)

Each user has his own profile which can be personalized with a picture. When
a user adds a picture for his profile, Skype creates in /tmp directory a
file named "skype_profile.jpg" in an insecure manner, without checking if
the file already exists and if it's a symbolic link.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-18 01:40:57 UTC
net-im please advise. 
Comment 2 Gustavo Felisberto (RETIRED) gentoo-dev 2005-07-18 06:35:13 UTC
Well. I really dont know how this can be handled. Right now skype in gentoo is
started via a wrapper script, maybe changing the script so that it will:
1-try to remove the file in /tmp
1.1-if it fails exit with error
2-create the file with correct permissions
3-Continue with normal startup

Any ideas if this is ok?
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-18 07:23:27 UTC
Gustavo we could also wait a bit to see wether upstream releases a fix. 
Comment 4 Colin Macdonald 2005-07-28 13:32:27 UTC
It seems this is fixed in 1.2.0.11 (bug #100611).  See the changelog:
bugfix: profile image file in /tmp not checked properly (thanks to Giovanni
Delvecchio for reporting)
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-28 14:06:37 UTC
net-im please bump. 
Comment 6 Karol Wojtaszek (RETIRED) gentoo-dev 2005-07-31 13:31:52 UTC
Bumped in portage.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-31 13:33:49 UTC
Thx Karol.