<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>107312</bug_id>
          
          <creation_ts>2005-09-26 12:12 0000</creation_ts>
          <short_desc>app-arch/arc: insecure temporary file creation</short_desc>
          <delta_ts>2005-10-04 05:56:00 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B4 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-09-26 12:12:14 0000</bug_when>
            <thetext>http://www.zataz.net/adviso/arc-09052005.txt

arc is missing a maintainer and metadata.xml</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-09-26 12:13:50 0000</bug_when>
            <thetext>Created an attachment (id=69284)
proposed-fix.patch

Joey Schulze &lt;joey@infodrom.org&gt; replied on Bugtray proposing this patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-09-26 12:15:15 0000</bug_when>
            <thetext>

*** This bug has been marked as a duplicate of 66251 ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-09-26 12:15:57 0000</bug_when>
            <thetext>sorry, that one went wrong</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-27 00:32:07 0000</bug_when>
            <thetext>vapier/solar: no maintainer, care to apply the patch ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-09-29 14:38:07 0000</bug_when>
            <thetext>(From update of attachment 69284)
this patch is all mangled

either way, there&apos;s a version upstream which is not in portage which has this
fix
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-09-29 15:22:03 0000</bug_when>
            <thetext>arc-5.21m now in portage</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-30 00:38:36 0000</bug_when>
            <thetext>Archs, please test and mark stable :
Target KEYWORDS : &quot;x86 ppc sparc alpha amd64 ppc64&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-09-30 02:39:59 0000</bug_when>
            <thetext>alpha keyword for free !!!!

Cheers,
Ferdy</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-09-30 10:11:03 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-09-30 11:18:30 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-09-30 11:21:36 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-09-30 13:09:46 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fuzzyray@gentoo.org</who>
            <bug_when>2005-09-30 13:19:37 0000</bug_when>
            <thetext>Stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-09-30 13:54:08 0000</bug_when>
            <thetext>Ready for GLSA vote</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-01 03:41:41 0000</bug_when>
            <thetext>This is information disclosure, not symlink. I tend to vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-10-02 10:10:32 0000</bug_when>
            <thetext>I tend to vote NO too. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-04 05:56:00 0000</bug_when>
            <thetext>Let&apos;s close it, since nobody else wants to vote... Please reopen if you disagree.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>69284</attachid>
            <date>2005-09-26 12:13 0000</date>
            <desc>proposed-fix.patch</desc>
            <filename>proposed-fix.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGFyY3N2Yy5jfsKgwqDCoDIwMDUtMDMtMTMgMTY6NDg6MDkuMDAwMDAwMDAwICswMTAwCisr
KyBhcmNzdmMuY8KgwqDCoMKgMjAwNS0wOS0xNyAwOTo0MTo1MS4wMDAwMDAwMDAgKzAyMDAKQEAg
LTE3LDYgKzE3LDkgQEAKwqDCoMKgwqDCoMKgwqDCoCBDb21wdXRlciBJbm5vdmF0aW9ucyBPcHRp
bWl6aW5nIEM4NgrCoCovCsKgI2luY2x1ZGUgPHN0ZGlvLmg+CisjaW5jbHVkZSA8c3lzL3R5cGVz
Lmg+CisjaW5jbHVkZSA8c3lzL3N0YXQuaD4KKyNpbmNsdWRlIDxmY250bC5oPgrCoCNpbmNsdWRl
ICJhcmMuaCIKwqAjaWbCoMKgwqDCoF9NVFMKwqAjaW5jbHVkZSA8bXRzLmg+CkBAIC01Miw3ICs1
NSwxMiBAQCBvcGVuYXJjKGNoZynCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgLyog
b3BlbiBhcmNoaXZlICovCsKgwqDCoMKgwqDCoMKgwqB9CsKgI2VuZGlmCsKgwqDCoMKgwqDCoMKg
wqBpZiAoY2hnKSB7wqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoC8qIGlmIG9wZW5pbmcgZm9y
IGNoYW5nZXMgKi8KLcKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoGlmICghKG5ldyA9IGZv
cGVuKG5ld25hbWUsIE9QRU5fVykpKQorwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgaW50
IGZkOworCivCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqBpZiAoKGZkID0gb3BlbihuZXdu
YW1lLCBPX0NSRUFUfE9fRVhDTHxPX1JEV1IsIFNfSVJFQUR8U19JV1JJVEUpKSA9PSAtMSkKK8Kg
wqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqBhcmNkaWUoIkNhbm5v
dCBjcmVhdGUgYXJjaGl2ZSBjb3B5OiAlcyIsIG5ld25hbWUpOworCivCoMKgwqDCoMKgwqDCoMKg
wqDCoMKgwqDCoMKgwqBpZiAoIShuZXcgPSBmZG9wZW4oZmQsIE9QRU5fVykpKQrCoMKgwqDCoMKg
wqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqDCoMKgwqBhcmNkaWUoIkNhbm5vdCBjcmVh
dGUgYXJjaGl2ZSBjb3B5OiAlcyIsIG5ld25hbWUpOwrCoArCoMKgwqDCoMKgwqDCoMKgY2hhbmdp
bmcgPSBjaGc7wqDCoMKgwqDCoMKgwqDCoMKgLyogbm90ZSBpZiBvcGVuIGZvciBjaGFuZ2VzICov
Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>