<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>201022</bug_id>
          <alias>CVE-2007-6209</alias>
          <creation_ts>2007-12-02 21:02 0000</creation_ts>
          <short_desc>app-shells/zsh &lt; 4.3.2-r3 insecure temporary file creation (CVE-2007-6209)</short_desc>
          <delta_ts>2008-03-06 09:55:25 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>py@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>pipping@gentoo.org</cc>
    
    <cc>tove@gentoo.org</cc>
    
    <cc>usata@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-12-02 21:02:22 0000</bug_when>
            <thetext>zsh provides a difflog.pl script in /usr/share/zsh/4.3.4/Util/difflog.pl which uses insecurely created files in /tmp, same kind of issue than bug #198231. Thanks to Elias Pipping for noticing.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-12-02 21:09:01 0000</bug_when>
            <thetext>Mamoru, do you know if upstream is aware of this? We could modify the feynmf patch, but having an official corrected release from upstream would probably be better. Any opinion?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-12-02 21:47:39 0000</bug_when>
            <thetext>(In reply to comment #1)
&gt; Mamoru, do you know if upstream is aware of this? We could modify the feynmf
&gt; patch, but having an official corrected release from upstream would probably be
&gt; better. Any opinion?
&gt; 

actually cc&apos;ing maintainer :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tove@gentoo.org</who>
            <bug_when>2007-12-03 18:09:55 0000</bug_when>
            <thetext>usata announced his retirement recently.

zsh devs are aware of the issue:
http://www.zsh.org/mla/workers/2007/msg01060.html and follow ups (especially &lt;http://www.zsh.org/mla/workers/2007/msg01065.html&gt;)

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-03 23:57:20 0000</bug_when>
            <thetext>Since the decision is going to be not to distribute that file, it should be removed from the ebuild.

Anyone in cc on this bug willing to maintain this baby? If not, we should ask the dev community.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tove@gentoo.org</who>
            <bug_when>2007-12-04 16:19:37 0000</bug_when>
            <thetext>I&apos;ve just added two new ebuilds without difflog.pl (4.3.2-r3 and 4.3.4-r1).
(BTW upstream has fixed the issue in their repo.)

=app-shells/zsh-4.3.2-r3 should be stabilized again. Removing difflog.pl is the only substantial change.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-04 17:53:23 0000</bug_when>
            <thetext>Arches, please test and mark stable app-shells/zsh-4.3.2-r3.
Target keywords : &quot;alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-12-04 20:17:03 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-12-04 20:19:40 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-12-04 21:07:49 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-12-05 00:41:39 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-12-05 11:19:04 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-12-06 05:07:04 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-12-08 23:36:58 0000</bug_when>
            <thetext>voting time. I tend to vote No since the script usage seems to be extremely unlikely, according to the zsh ml.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-12-09 01:28:43 0000</bug_when>
            <thetext>voting NO, too. closing.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-06 09:55:25 0000</bug_when>
            <thetext>Does not affect current (2008.0) release. Removing release.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>