<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>212145</bug_id>
          <alias>CVE-2008-0777</alias>
          <creation_ts>2008-03-03 01:32 0000</creation_ts>
          <short_desc>sys-freebsd/freebsd-sources &lt; 6.2-r4 sendfile(2) write-only file permission bypass (CVE-2008-0777)</short_desc>
          <delta_ts>2008-05-17 20:37:37 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://security.freebsd.org/advisories/FreeBSD-SA-08:03.sendfile.asc</bug_file_loc>
          <status_whiteboard>~3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>trivial</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bsd@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-03 01:32:02 0000</bug_when>
            <thetext>CVE-2008-0777 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0777):
  The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access
  flags of the file descriptor used for sending a file, which allows local
  users to read the contents of write-only files.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-03 01:33:27 0000</bug_when>
            <thetext>BSD herd, please act.

This is the third security bug that is now open, and the others are not moving at all. Are you maintaining the Gentoo BSD port, or can/should this be p.masked?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-05-09 14:26:41 0000</bug_when>
            <thetext>(In reply to comment #1)
&gt; BSD herd, please act.
&gt; 
&gt; This is the third security bug that is now open, and the others are not moving
&gt; at all. Are you maintaining the Gentoo BSD port, or can/should this be
&gt; p.masked?
&gt; 

*ping*</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aballier@gentoo.org</who>
            <bug_when>2008-05-17 19:55:28 0000</bug_when>
            <thetext>6.2-r4 has the patch</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-05-17 20:37:37 0000</bug_when>
            <thetext>thanks, closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>