<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>102151</bug_id>
          
          <creation_ts>2005-08-11 12:22 0000</creation_ts>
          <short_desc>kde-base/kdeedu temp file vulnerability in langen2kvtml</short_desc>
          <delta_ts>2005-08-18 09:40:44 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <bug_file_loc>http://www.kde.org/info/security/advisory-20050815-1.txt</bug_file_loc>
          <status_whiteboard>B3? [stable] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>caleb@gentoo.org</cc>
    
    <cc>carlo@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-11 12:22:04 0000</bug_when>
            <thetext>KDE Security Advisory: langen2kvtml tempfile vulnerability 
Original Release Date: 2008-08-15 
URL: http://www.kde.org/info/security/advisory-20050815-1.txt 
 
0. References 
 
 
 
1. Systems affected: 
 
        All KDE releases starting from KDE 3.0 up to including 
        KDE 3.4.2. 
 
 
2. Overview: 
 
        Ben Burton notified the KDE security team about several 
        tempfile handling related vulnerabilities in langen2kvtml, 
        a conversion script for kvoctrain. The script must 
        be manually invoked.  
 
        The script uses known filenames in /tmp which allow an 
        local attacker to overwrite files writeable by the 
        user invoking the conversion script. 
 
3. Impact: 
 
        A local file can overwrite files and possibly elevate 
        privileges. 
 
 
4. Solution: 
 
        Source code patches have been made available which fix these 
        vulnerabilities. Contact your OS vendor / binary package provider 
        for information about how to obtain updated binary packages. 
 
 
5. Patch: 
 
        Patch for KDE 3.4.2 is available from  
        ftp://ftp.kde.org/pub/kde/security_patches : 
 
        XXX 
 
        Patch for KDE 3.3.1 is available from  
        ftp://ftp.kde.org/pub/kde/security_patches : 
 
        651fba579516ea947fbefee373f40a6c  post-3.3.1-kdegraphics.diff</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-11 12:23:28 0000</bug_when>
            <thetext>Created an attachment (id=65692)
post-3.4.2-kdeedu.diff

Proposed upstream patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-11 12:35:08 0000</bug_when>
            <thetext>RH seems to have accidentially put out updated kdeedu packages (though I 
haven&apos;t actually found it yet). If correct this is SEMIPUBLIC instead of 
CONFIDENTIAL.  </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-11 13:12:52 0000</bug_when>
            <thetext>Fedora updates here: 
 
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/i386/kdeedu-3.4.2-0.fc4.2.i386.rpm </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-08-14 16:37:19 0000</bug_when>
            <thetext>&lt;&lt;&lt; kdeedu-3.3.2-r2.ebuild
&lt;&lt;&lt; kdeedu-3.4.1-r1.ebuild
&lt;&lt;&lt; kvoctrain-3.4.1-r1.ebuild

are marked x86, the other archs are asked to follow.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2005-08-14 17:07:24 0000</bug_when>
            <thetext>Well, i don&apos;t have a good feeling that these patches are in portage but since
it&apos;s semi-public, i just hope that it&apos;s ok. Would be too late now, anyways.

Arches, please test and mark kdeedu-3.3.2-r2 stable. if kde-3.4.1 was stable on
your arch, please do the same with kdeedu-3.4.1-r1 and kvoctrain-3.4.1-r1.
Thanks a lot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-14 21:52:18 0000</bug_when>
            <thetext>Removing arches and adding arch security liaisons instead. Please test and 
mark stable. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-08-14 22:27:20 0000</bug_when>
            <thetext>This is now handled on the public bug #102577 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-08-15 05:58:41 0000</bug_when>
            <thetext>removing as it is stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-08-15 06:10:31 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2005-08-15 06:43:50 0000</bug_when>
            <thetext>x86 already there</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-08-18 09:40:44 0000</bug_when>
            <thetext>Closing, as we are done here.

*** This bug has been marked as a duplicate of 102577 ***</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>65692</attachid>
            <date>2005-08-11 12:23 0000</date>
            <desc>post-3.4.2-kdeedu.diff</desc>
            <filename>post-3.4.2-kdeedu.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IGt2b2N0cmFpbi9rdm9jdHJhaW4vbGFuZ2VuMmt2dG1sCj09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIGt2
b2N0cmFpbi9rdm9jdHJhaW4vbGFuZ2VuMmt2dG1sCShyZXZpc2lvbiA0NDM5NzUpCisrKyBrdm9j
dHJhaW4va3ZvY3RyYWluL2xhbmdlbjJrdnRtbAkod29ya2luZyBjb3B5KQpAQCAtODksNiArODks
OSBAQAogCiByZXF1aXJlICJmbHVzaC5wbCI7CiB1c2UgR2V0b3B0OjpMb25nOwordXNlIEZpbGU6
OlRlbXAgcXcodGVtcGRpcik7CitteSAkdG1wZGlyID0gdGVtcGRpcihURU1QRElSID0+IDEsIENM
RUFOVVAgPT4gMSApOworCiAkLz0iXHJcbiI7CSMgd2Ugd29yayB3aXRoIGRvcyBmaWxlcwogCiAj
CkBAIC0xNjUsMTAgKzE2OCw2IEBACiAgICAgJGNvdW50cnk9IkdCIjsKIH0KIAotIyBBbGwgbG9n
Z2luZyBpbmZvcm1hdGlvbiBnb2VzIGludG8gdGhpcyBmaWxlCi0kbG9nZmlsZSA9ICIvdG1wL2xh
bmdlbjJrdnRtbC5sb2ciOwotb3BlbihMT0csICI+JGxvZ2ZpbGUiKSB8fCBkaWUgIkNhbm5vdCBj
cmVhdGUgJGxvZ2ZpbGU6ICQhIjsKLQogJnByaW50Zmx1c2goU1RET1VULCJXYWl0aW5nIGZvciBn
ZW5lcmF0aW5nIGZpbGVzIC4uLlxuIik7CiAkdG1wMT0kI0FSR1YrMTsKICZwcmludGZsdXNoKFNU
RE9VVCwiLi4uICR0bXAxIGZpbGVzIGdpdmVuIHZpYSBjb21tYW5kIGxpbmUgLi4uXG4iKTsKQEAg
LTE3OCwxMyArMTc3LDExIEBACiAgICAgaWYgKCRwcm94eSkgewogICAgICAgICAmcHJpbnRmbHVz
aChTVERPVVQsIi4uLiB1c2luZyBwcm94eSBzZXJ2aWNlICRwcm94eSAuLi5cbiIpOwogICAgIH0K
LSAgICBgbHdwLXJlcXVlc3QgJHByb3h5IGh0dHA6Ly93d3cudm9rYWJlbG4uZGUvZmlsZXMvVm9j
LSRjb3VudHJ5LnppcCA+L3RtcC9Wb2MtJGNvdW50cnkuemlwYDsKLSAgICAjIHVuemlwIC11IHVw
ZGF0ZSBvbmx5IQotICAgICMgdW56aXAgLW8gb3ZlcndyaXRlIQotICAgIGB1bnppcCAtdSAvdG1w
L1ZvYy0kY291bnRyeS56aXAgPi90bXAvdW56aXAubG9nYDsKKyAgICBgbHdwLXJlcXVlc3QgJHBy
b3h5IGh0dHA6Ly93d3cudm9rYWJlbG4uZGUvZmlsZXMvVm9jLSRjb3VudHJ5LnppcCA+JHRtcGRp
ci9Wb2MtJGNvdW50cnkuemlwYDsKICAgICAmcHJpbnRmbHVzaChTVERPVVQsIi4uLiB1cGRhdGlu
ZyBWb2MtJGNvdW50cnkuemlwIC4uLlxuIik7CiAgICAgJC89IlxuIjsJIyB3ZSB3b3JrIHdpdGgg
YSB1bml4IGZpbGUKLSAgICBvcGVuKFpJUCwiPC90bXAvdW56aXAubG9nIik7CisgICAgIyB1bnpp
cCAtdSB1cGRhdGUgb25seSEKKyAgICBvcGVuKFpJUCwidW56aXAgLXUgJHRtcGRpci9Wb2MtJGNv
dW50cnkuemlwIHwiKTsKICAgICB3aGlsZSg8WklQPikgewogCWNob21wOwogCWlmKCAvdm9jLyAp
IHsKQEAgLTE5NCwyMCArMTkxLDE2IEBACiAJfQogICAgIH0KICAgICBjbG9zZShaSVApOwotICAg
IHVubGluaygiL3RtcC91bnppcC5sb2ciKTsKICAgICAkLz0iXHJcbiI7CSMgd2Ugd29yayB3aXRo
IGEgZG9zIGZpbGUKIH0KIAogZm9yIG15ICRmaWxlIChAcmVzLCBAQVJHVikgewogICAgICR2b2Nm
aWxlID0gJGZpbGU7Ci0gICAgJnByaW50Zmx1c2goTE9HLCIuLi4gZ2VuZXJhdGluZyBcIiRrdnRm
aWxlXCIuLi5cbiIpOwogICAgICRsYW5nCQk9ICIiOwkJIyBpbml0aWFsbHkgdW5zZXQKICAgICAk
ZmlsZXN0YWdlCT0gMDsJCSMgZmlsZSBzdGFnZQogICAgICZwcm9jZXNzX3ZvY2ZpbGUoJHZvY2Zp
bGUpOwogfQogcHJpbnQgU1RERVJSICIuLi5cdEFsbCBDb21wbGV0ZS5cbiI7Ci0mcHJpbnRmbHVz
aChMT0csIlxuQWxsIENvbXBsZXRlLlxuIik7Ci1jbG9zZShMT0cpOwogCiBleGl0OwogCg==
</data>        

          </attachment>
    </bug>

</bugzilla>