<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>45646</bug_id>
          
          <creation_ts>2004-03-24 14:26 0000</creation_ts>
          <short_desc>GNU Automake &lt;1.8.3: Insecure Temporary Directory Creation Symbolic Link Vulnerability</short_desc>
          <delta_ts>2004-04-08 07:36:10 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>GLSA Errors</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.securityfocus.com/bid/9816/info/</bug_file_loc>
          
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>schaedpq2@gmx.de</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>base-system@gentoo.org</cc>
    
    <cc>mr_bones_@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>schaedpq2@gmx.de</who>
            <bug_when>2004-03-24 14:26:00 0000</bug_when>
            <thetext>It has been reported that GNU Automake may be prone to a symbolic link vulnerability that may allow an attacker to modify data or gain elevated privileges on a vulnerable system.

Reproducible: Didn&apos;t try
Steps to Reproduce:
1.
2.
3.




From bugtraqs database:
http://www.securityfocus.com/bid/9816/discussion/

It has been reported that GNU Automake may be prone to a symbolic link
vulnerability that may allow an attacker to modify data or gain elevated
privileges on a vulnerable system. This issue results due to insecure creation
of directories during compilation. The attacker may potentially create symbolic
links in the place of files contained in the affected directories, which may
potentially lead to elevated privileges due to modification of data.

GNU Automake versions prior to 1.8.3 are reported to be affected by this
vulnerability.

I think this is not an issue of great significance but IMHO it should be kept in
mind, perhaps there is a possibility to update to 1.8.3 and get rid of older
versions or at least to get 1.8.3 into portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-03-24 18:18:25 0000</bug_when>
            <thetext>-	epatch ${FILESDIR}/${P}-infopage-namechange.patch
+	epatch ${FILESDIR}/${PN}-1.8.2-infopage-namechange.patch

In portage as
KEYWORDS=&quot;~amd64 ~x86 ~ppc ~sparc ~alpha ~mips ~hppa ~ia64 ~ppc64 ~s390&quot;

Please test.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>avenj@gentoo.org</who>
            <bug_when>2004-03-26 17:24:21 0000</bug_when>
            <thetext>Stable on AMD64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2004-03-26 17:54:50 0000</bug_when>
            <thetext>Stable on sparc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-03-26 18:55:17 0000</bug_when>
            <thetext>Removing arch-maintainers from CC list and leaving remaining 
arches as well as adding base-system.

Note to self: s390@gentoo.org has no alias</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>agriffis@gentoo.org</who>
            <bug_when>2004-03-29 09:09:22 0000</bug_when>
            <thetext>stable on alpha and ia64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pylon@gentoo.org</who>
            <bug_when>2004-03-30 16:05:29 0000</bug_when>
            <thetext>automake-1.8.3 is now stable on ppc.  Removing from Cc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>avenj@gentoo.org</who>
            <bug_when>2004-04-02 10:30:11 0000</bug_when>
            <thetext>Marked stable on x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-04-03 12:41:20 0000</bug_when>
            <thetext>Major arches covered now.

automake-1.8.3:
KEYWORDS=&quot;amd64 x86 ppc sparc alpha ~mips ~hppa ia64 ~ppc64 ~s390&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-04-04 03:05:08 0000</bug_when>
            <thetext>Stable on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2004-04-08 02:57:07 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-04-08 07:36:10 0000</bug_when>
            <thetext>GLSA 200404-08</thetext>
          </long_desc>
      
    </bug>

</bugzilla>