<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>68406</bug_id>
          
          <creation_ts>2004-10-21 07:58 0000</creation_ts>
          <short_desc>sys-fs/lvm-user: Insecure tmpfile use</short_desc>
          <delta_ts>2004-11-11 13:28:57 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136308</bug_file_loc>
          <status_whiteboard>B3 [glsa] koon</status_whiteboard>
          
          <priority>P1</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>base-system@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-21 07:58:37 0000</bug_when>
            <thetext>CAN-2004-0972

The lvmcreate_initrd script in the lvm package in Trustix Secure Linux
1.5 through 2.1, and possibly other operating systems, allows local
users to overwrite files via a symlink attack on temporary files.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-21 08:06:58 0000</bug_when>
            <thetext>Created an attachment (id=42316)
Patch from RedHat bug

Patch from RedHat</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-22 08:11:11 0000</bug_when>
            <thetext>We have two lvm packages in our tree, lvm-user for LVM 1.* and lvm2 for LVM 2.*. The script is only in LVM 1.* releases. So we should either remove the package or fix it :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-10-30 09:27:54 0000</bug_when>
            <thetext>base-system: please either fix this or remove lvm-user altogether. I&apos;m sure you prefer we don&apos;t mess with it ourselves :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2004-11-02 02:39:43 0000</bug_when>
            <thetext>Debian bug report: 
&lt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=279229&gt;

Diff from Ubuntu Linux (full diff to orig package including typical Debian stuff): &lt;http://security.ubuntu.com/ubuntu/pool/main/l/lvm10/lvm10_1.0.8-4ubuntu1.1.diff.gz&gt;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-05 06:12:26 0000</bug_when>
            <thetext>Patch in attachment applies cleanly to lvm-user-1.0.7-r1.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2004-11-09 21:56:56 0000</bug_when>
            <thetext>1.0.7-r2 is in portage with the fix</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-11-09 23:03:08 0000</bug_when>
            <thetext>Arches please mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2004-11-10 04:48:05 0000</bug_when>
            <thetext>What stable? vapier bumped every one to stable directly...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-11-10 04:58:18 0000</bug_when>
            <thetext>Sune obviously needs some rest :) Sorry for the inconvenience...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-11-11 13:28:57 0000</bug_when>
            <thetext>GLSA 200411-22</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>42316</attachid>
            <date>2004-10-21 08:06 0000</date>
            <desc>Patch from RedHat bug</desc>
            <filename>lvm-1.0.8-tempfile.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">ZGlmZiAtdXIgTFZNLm9yaWcvMS4wLjgvdG9vbHMvbHZtY3JlYXRlX2luaXRyZCBMVk0vMS4wLjgv
dG9vbHMvbHZtY3JlYXRlX2luaXRyZAotLS0gTFZNLm9yaWcvMS4wLjgvdG9vbHMvbHZtY3JlYXRl
X2luaXRyZAkyMDAzLTExLTE3IDE2OjU4OjU2LjAwMDAwMDAwMCArMDEwMAorKysgTFZNLzEuMC44
L3Rvb2xzL2x2bWNyZWF0ZV9pbml0cmQJMjAwNC0wOS0xMyAxMjowNzoyMy4wMDAwMDAwMDAgKzAy
MDAKQEAgLTIzMyw2ICsyMzMsMTAgQEAKICMgcnVuIG91dCBvZiByb29tIG9uIHRoZSByYW1kaXNr
IHdoaWxlIHN0cmlwcGluZyB0aGUgbGlicmFyaWVzLgogZWNobyAiJGNtZCAtLSBzdHJpcHBpbmcg
c2hhcmVkIGxpYnJhcmllcyIKIG1rZGlyICRUTVBMSUIKK2lmIFsgJD8gLW5lIDAgXTsgdGhlbgor
ICAgZWNobyAiJGNtZCAtLSBFUlJPUiBtYWtpbmcgJFRNUExJQiIKKyAgIGNsZWFudXAgMQorZmkK
IGZvciBMSUIgaW4gJFNITElCUzsgZG8KICAgIHZlcmJvc2UgImNvcHkgJExJQiB0byAkVE1QTElC
JExJQiIKICAgIG1rZGlyIC1wIGBkaXJuYW1lICRUTVBMSUIkTElCYAo=
</data>        

          </attachment>
    </bug>

</bugzilla>