<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>119309</bug_id>
          
          <creation_ts>2006-01-17 10:13 0000</creation_ts>
          <short_desc>app-text/antiword - insecure temporary file (CVE-2005-3126)</short_desc>
          <delta_ts>2006-01-22 17:09:13 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B3 [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>seemant@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-01-17 10:13:51 0000</bug_when>
            <thetext>from DSA 945-1:

Javier Fern</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-01-17 10:13:51 0000</bug_when>
            <thetext>from DSA 945-1:

Javier Fernández-Sanguino Peña from the Debian Security Audit project
discovered that two scripts in antiword, utilities to convert Word
files to text and Postscript, create a temporary file in an insecure
fashion.



0.36.1 is affected as well and the relevant parts of the patch below should apply.

http://security.debian.org/pool/updates/main/a/antiword/antiword_0.35-2sarge1.diff.gz</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-01-17 11:50:38 0000</bug_when>
            <thetext>Seemant please provide an updated ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2006-01-18 06:01:54 0000</bug_when>
            <thetext>Created an attachment (id=77417)
updated ebuild

updated ebuild -- see distfiles in /space/distfiles-local on toucan</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2006-01-18 06:02:13 0000</bug_when>
            <thetext>Sune: there it is.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2006-01-18 06:11:26 0000</bug_when>
            <thetext>Actually, it&apos;s committed into cvs.  Please test and mark stable as appropriate.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-01-18 07:02:23 0000</bug_when>
            <thetext>Arches please test and mark stable
Target KEYWORDS=&quot;alpha amd64 ~hppa ppc ~ppc-macos ppc64 sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-01-18 08:38:36 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2006-01-18 08:55:52 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2006-01-18 09:44:58 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fuzzyray@gentoo.org</who>
            <bug_when>2006-01-18 11:22:08 0000</bug_when>
            <thetext>Stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2006-01-18 11:34:57 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2006-01-19 17:14:51 0000</bug_when>
            <thetext>alpha stable. 

Sorry about the delay :(</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-01-22 15:47:41 0000</bug_when>
            <thetext>glsa vote for this one, tend to say yes.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2006-01-22 17:04:21 0000</bug_when>
            <thetext>background: only the wrapper script to make drag and drop work for KDE1 users is affected, ie if you use antiword from command line or in KDE3, you&apos;re safe.

so, as very few users are likely to be affected, i would vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-01-22 17:09:13 0000</bug_when>
            <thetext>Correcting my vote to a no and closing the bug as fixed with no glsa. As always, feel free to reopen if you disagree.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>77417</attachid>
            <date>2006-01-18 06:01 0000</date>
            <desc>updated ebuild</desc>
            <filename>antiword-0.37.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA1IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6IC92YXIvY3Zzcm9vdC9nZW50b28teDg2L2FwcC10ZXh0L2FudGl3b3JkL2FudGl3b3JkLTAu
MzYuMS5lYnVpbGQsdiAxLjQgMjAwNS8wOC8zMSAxMDoyMDoxMCBncm9iaWFuIEV4cCAkCgppbmhl
cml0IGV1dGlscwoKSVVTRT0ia2RlIgpQQVRDSFZFUj0wLjEKREVTQ1JJUFRJT049ImZyZWUgTVMg
V29yZCByZWFkZXIiCkhPTUVQQUdFPSJodHRwOi8vd3d3LndpbmZpZWxkLmRlbW9uLm5sIgpTUkNf
VVJJPSJodHRwOi8vd3d3LndpbmZpZWxkLmRlbW9uLm5sL2xpbnV4LyR7UH0udGFyLmd6CgltaXJy
b3I6Ly9nZW50b28vJHtQfS1nZW50b28tJHtQQVRDSFZFUn0udGFyLmJ6MiIKClNMT1Q9IjAiCkxJ
Q0VOU0U9IkdQTC0yIgpLRVlXT1JEUz0ifmFscGhhIH5hbWQ2NCB+aHBwYSB+cHBjIH5wcGMtbWFj
b3MgfnBwYzY0IH5zcGFyYyB+eDg2IgoKREVQRU5EPSJ2aXJ0dWFsL2dob3N0c2NyaXB0IgoKUEFU
Q0hESVI9JHtXT1JLRElSfS9nZW50b28tYW50aXdvcmQvcGF0Y2hlcwoKc3JjX3VucGFjaygpIHsK
CXVucGFjayAke0F9IDsgY2QgJHtTfQoJRVBBVENIX1NVRkZJWD0iZGlmZiIgXAoJCWVwYXRjaCAk
e1BBVENIRElSfQp9CgpzcmNfY29tcGlsZSgpIHsKCWVtYWtlIE9QVD0iJHtDRkxBR1N9IiB8fCBk
aWUKfQoKc3JjX2luc3RhbGwoKSB7CgltYWtlIERFU1RESVI9JHtEfSBnbG9iYWxfaW5zdGFsbCB8
fCBkaWUKCgl1c2Uga2RlIHx8IHJtIC1mICR7RH0vdXNyL2Jpbi9rYW50aXdvcmQKCglpbnNpbnRv
IC91c3Ivc2hhcmUvJHtQTn0vZXhhbXBsZXMKCWRvaW5zIERvY3MvdGVzdGRvYy5kb2MgRG9jcy9h
bnRpd29yZC5waHAKCgljZCBEb2NzCglkb21hbiBhbnRpd29yZC4xCglkb2RvYyBDT1BZSU5HIENo
YW5nZUxvZyBFeG1oIEVtYWNzIEZBUSBIaXN0b3J5IE5ldHNjYXBlIFwKCVFhbmRBIFJlYWRNZSBN
b3ppbGxhIE11dHQKfQo=
</data>        

          </attachment>
    </bug>

</bugzilla>