<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>68405</bug_id>
          
          <creation_ts>2004-10-21 07:57 0000</creation_ts>
          <short_desc>app-arch/gzip: Insecure tmpfile use</short_desc>
          <delta_ts>2009-07-13 22:32:34 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.trustix.org/errata/2004/0050</bug_file_loc>
          <status_whiteboard>B3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>beejay@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-21 07:57:23 0000</bug_when>
            <thetext>CAN-2004-0970

The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package in
Trustix Secure Linux 1.5 through 2.1, and possibly other operating
systems, allows local users to overwrite files via a symlink attack on
temporary files.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-21 08:17:03 0000</bug_when>
            <thetext>We use an unpatched zdiff that looks vulnerable :

---------------snip----------------
gzip -cdfq &quot;$2&quot; &gt; /tmp/&quot;$F&quot;.$$ || exit
---------------snip----------------

However there doesn&apos;t seem to be any patches out there for that one... Maybe lewk could find one ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2004-10-24 17:07:17 0000</bug_when>
            <thetext>Created an attachment (id=42521)
zdiff.in-tempfile.patch

Patch to fix tempfile vulnerabilities in zdiff.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2004-10-24 17:10:12 0000</bug_when>
            <thetext>base-system, please verify and apply patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-25 04:50:12 0000</bug_when>
            <thetext>Patch looks good to me...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-10-26 16:27:39 0000</bug_when>
            <thetext>Old - gzip-1.3.5-r1
KEYWORDS=&quot;x86 ppc sparc mips alpha arm hppa amd64 ~ia64 ~ppc64 ~s390&quot;

New - gzip-1.3.5-r2
KEYWORDS=&quot;~x86 ~ppc ~sparc ~mips ~alpha ~arm ~hppa ~amd64 ~ia64 ~ppc64 ~s390&quot;

ppc64/ia64/s390 still have 1.3.3-r4 stable.

The changes are so minor that I would think the arches would prefer to have this 
go right into it&apos;s stable if it was stable on 1.3.5-r1. But for GLSA&apos;s and tools 
it&apos;s always best to rev bump.

Arch maintainers in the future what do you prefer when the changes are so tiny 
and dont effect the object code?
1) That you always be the one todo it.
2) That other I/we use our best judgement and save you a few mails &amp; cpu cycles.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2004-10-26 16:28:44 0000</bug_when>
            <thetext>Oh arch-maintainers please test and mark gzip-1.3.5-r2 as stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2004-10-26 17:00:10 0000</bug_when>
            <thetext>sparc tasty.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lv@gentoo.org</who>
            <bug_when>2004-10-26 18:03:48 0000</bug_when>
            <thetext>stable on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>josejx@gentoo.org</who>
            <bug_when>2004-10-26 19:52:37 0000</bug_when>
            <thetext>Tested and marked stable on ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2004-10-27 01:48:36 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2004-10-27 16:04:40 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2004-10-27 16:56:48 0000</bug_when>
            <thetext>stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-28 00:30:06 0000</bug_when>
            <thetext>Only zdiff is affected, so it&apos;s a B3 : security, please vote on GLSA need.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-10-28 05:18:19 0000</bug_when>
            <thetext>arm/hppa/ia64/s390 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>klieber@gentoo.org</who>
            <bug_when>2004-10-28 11:57:38 0000</bug_when>
            <thetext>zdiff is fairly obscure...I&apos;ll go with no on this one.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2004-10-28 12:03:10 0000</bug_when>
            <thetext>Closing without GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tgall@gentoo.org</who>
            <bug_when>2004-10-30 08:59:13 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>42521</attachid>
            <date>2004-10-24 17:07 0000</date>
            <desc>zdiff.in-tempfile.patch</desc>
            <filename>zdiff.in-tempfile.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGd6aXAtMS4zLjUvemRpZmYuaW4ub3JpZwkyMDA0LTEwLTI0IDE5OjUyOjE2Ljg3NTk4NzIw
OCAtMDQwMAorKysgZ3ppcC0xLjMuNS96ZGlmZi5pbgkyMDA0LTEwLTI0IDIwOjAwOjI1LjY4NTY3
Njg0MCAtMDQwMApAQCAtMzUsNiArMzUsMTAgQEAKIAllY2hvICJVc2FnZTogJHByb2cgWyR7Y29t
cH1fb3B0aW9uc10gZmlsZSBbZmlsZV0iCiAJZXhpdCAyCiBmaQordG1wPWB0ZW1wZmlsZSAtZCAv
dG1wIC1wIGd6YCB8fCB7CisgICAgICBlY2hvICdjYW5ub3QgY3JlYXRlIGEgdGVtcG9yYXJ5IGZp
bGUnID4mMgorICAgICAgZXhpdCAxCit9CiBzZXQgJEZJTEVTCiBpZiB0ZXN0ICQjIC1lcSAxOyB0
aGVuCiAJRklMRT1gZWNobyAiJDEiIHwgc2VkICdzL1stLl1belp0Z2FdKiQvLydgCkBAIC00Nywx
MSArNTEsMTEgQEAKIAkgICAgICAgICpbLS5dZ3oqIHwgKlstLl1belpdIHwgKi50W2dhXXopCiAJ
CQlGPWBlY2hvICIkMiIgfCBzZWQgJ3N8LiovfHw7c3xbLS5dW3padGdhXSp8fCdgCiAJCQlzZXQg
LUMKLQkJCXRyYXAgJ3JtIC1mIC90bXAvIiRGIi4kJDsgZXhpdCAyJyBIVVAgSU5UIFBJUEUgVEVS
TSAwCi0JCQlnemlwIC1jZGZxICIkMiIgPiAvdG1wLyIkRiIuJCQgfHwgZXhpdAotICAgICAgICAg
ICAgICAgICAgICAgICBnemlwIC1jZGZxICIkMSIgfCAkY29tcCAkT1BUSU9OUyAtIC90bXAvIiRG
Ii4kJAorCQkJdHJhcCAncm0gLWYgJHRtcDsgZXhpdCAyJyBIVVAgSU5UIFBJUEUgVEVSTSAwCisJ
CQlnemlwIC1jZGZxICIkMiIgPiAkdG1wIHx8IGV4aXQKKwkJCWd6aXAgLWNkZnEgIiQxIiB8ICRj
b21wICRPUFRJT05TIC0gJHRtcAogICAgICAgICAgICAgICAgICAgICAgICAgU1RBVD0iJD8iCi0J
CQkvYmluL3JtIC1mIC90bXAvIiRGIi4kJCB8fCBTVEFUPTIKKwkJCS9iaW4vcm0gLWYgJHRtcCB8
fCBTVEFUPTIKIAkJCXRyYXAgLSBIVVAgSU5UIFBJUEUgVEVSTSAwCiAJCQlleGl0ICRTVEFUOzsK
IAo=
</data>        

          </attachment>
    </bug>

</bugzilla>