<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>155901</bug_id>
          
          <creation_ts>2006-11-21 16:36 0000</creation_ts>
          <short_desc>app-arch/tar symlink directory traversal? (CVE-2006-6097)</short_desc>
          <delta_ts>2007-02-11 10:24:09 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050812.html</bug_file_loc>
          <status_whiteboard>A2? [glsa+] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>tomk@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>cornet@sheepy.org</cc>
    
    <cc>passnet@zmail.ru</cc>

      

      
          <long_desc isprivate="0">
            <who>tomk@gentoo.org</who>
            <bug_when>2006-11-21 16:36:19 0000</bug_when>
            <thetext>It&apos;s possible to create symlinks to arbitrary locations on the filesystem within a tarball using the GNUTYPE_NAMES record name. This is demonstrated in the FD post specified.

Also this has been verified by a Gentoo user here: http://sheepy.org/node/23

For all intents and purposes you can can s/rootdo/sudo/g in that report (He&apos;s got some crazy scripts seeing as he&apos;s a veteran Gentoo user :) I&apos;ve also verified this exploit locally.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-21 23:07:09 0000</bug_when>
            <thetext>Base system please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-24 11:44:15 0000</bug_when>
            <thetext>Proposed fix is here:

https://savannah.gnu.org/bugs/download.php?file_id=11327</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-11-24 11:45:39 0000</bug_when>
            <thetext>And upstream bug: https://savannah.gnu.org/bugs/index.php?18355</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-11-28 01:39:14 0000</bug_when>
            <thetext>mhh this is evil, tricking somebody into extracting a tar file is easy.

please bump</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-11-29 00:38:32 0000</bug_when>
            <thetext>*** Bug 156578 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-11-30 11:26:40 0000</bug_when>
            <thetext>base-system, we are behind schedule, please bump!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2006-12-02 14:59:58 0000</bug_when>
            <thetext>cry me a river

1.16-r2 is in portage with the change that actually went into upstream cvs</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-12-03 03:56:55 0000</bug_when>
            <thetext>arch teams, please test and stable 1.16-r2</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2006-12-03 07:12:56 0000</bug_when>
            <thetext>x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-12-03 10:33:05 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-12-03 11:33:56 0000</bug_when>
            <thetext>And you, SPARC&apos;d me all night long....</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2006-12-03 14:29:00 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2006-12-06 00:19:35 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ahf@0x90.dk</who>
            <bug_when>2006-12-06 13:06:05 0000</bug_when>
            <thetext>Stable on MIPS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ahf@0x90.dk</who>
            <bug_when>2006-12-06 13:35:18 0000</bug_when>
            <thetext>Argh, forgot Alpha. Alpha is stable too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dang@gentoo.org</who>
            <bug_when>2006-12-08 10:41:28 0000</bug_when>
            <thetext>amd64 done, sorry for the delay.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-12-11 13:56:53 0000</bug_when>
            <thetext>GLSA 200612-10

thanks everyone</thetext>
          </long_desc>
      
    </bug>

</bugzilla>