<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>191643</bug_id>
          
          <creation_ts>2007-09-08 01:50 0000</creation_ts>
          <short_desc>app-crypt/coolkey &lt; 1.1.0-r1 file and directory permission flaw (CVE-2007-4129)</short_desc>
          <delta_ts>2007-09-08 09:03:27 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>https://bugzilla.redhat.com/show_bug.cgi?id=251774</bug_file_loc>
          <status_whiteboard>~3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>trivial</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>crypto@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-08 01:50:12 0000</bug_when>
            <thetext>According to Steve Grubb in Redhat #251774:
  It looks like coolkey creates /tmp/.pk11ipc1 as a world writable directory
  without the sticky bit. And...it creates the files under that potentially as
  world writable with the execute bit turned on or uses the file without any
  sanity check. coolkey runs as root sometimes and that makes it susceptible to
  doing symlink attacks.

The only version in the tree is unstable at the moment, however.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-09-08 07:58:20 0000</bug_when>
            <thetext>seems that redhat issued a patch. crypto, please provide a fixed ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>alonbl@gentoo.org</who>
            <bug_when>2007-09-08 08:21:26 0000</bug_when>
            <thetext>Added: coolkey-1.1.0-r1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-09-08 09:03:27 0000</bug_when>
            <thetext>thanks. closing without glsa.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>