<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>79844</bug_id>
          
          <creation_ts>2005-01-28 07:07 0000</creation_ts>
          <short_desc>app-arch/cpio possible permission issue</short_desc>
          <delta_ts>2005-02-06 18:38:03 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://savannah.gnu.org/patch/index.php?func=detailitem&amp;item_id=3690</bug_file_loc>
          <status_whiteboard>A4 [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>ppc-macos@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-28 07:07:24 0000</bug_when>
            <thetext>Candidate: CAN-1999-1572
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-1999-1572
Reference: MISC:http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391

cpio on FreeBSD 2.1.0, and possibly other operating systems, uses a 0
umask when creating files using the -O (archive) option, which creates
the files with mode 0666 and allows local users to read or overwrite
those files.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-28 07:07:53 0000</bug_when>
            <thetext>Vapier please check and advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-01-28 20:20:27 0000</bug_when>
            <thetext>example test shows same misbehavior with cpio-2.6</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-01-28 20:53:43 0000</bug_when>
            <thetext>2.6-r1 has the tiny patch to fix this ... i guess if we want to consider this as a serious issue, we&apos;ll need the arch guys come in and push 2.6-r1 to stable ... we&apos;ve had 2.5.90 since Dec 17 2004 and the actual 2.6 release since Jan 03 2005 ... all known issues were fixed with the 2.6 release so it should be a sane candidate for stable

i also filed a bug with upstream GNU cpio to have this added upstream</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-01-28 23:13:07 0000</bug_when>
            <thetext>Thx spanKY, please mark stable for sh.

Arches please test and mark 2.6-r1 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-01-29 00:48:41 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-01-29 02:15:54 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>luckyduck@gentoo.org</who>
            <bug_when>2005-01-29 07:51:40 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2005-01-29 09:43:44 0000</bug_when>
            <thetext>Stable on sparc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-01-29 19:51:20 0000</bug_when>
            <thetext>arm/hppa/ia64/s390/sh/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-01-30 11:34:53 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-01-31 13:42:46 0000</bug_when>
            <thetext>Please vote on GLSA... I don&apos;t think one is needed. Yes it&apos;s a bug leading to errors but I don&apos;t see where it&apos;s a vulnerability...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-02-02 11:03:18 0000</bug_when>
            <thetext>Debian released an advisory:

http://www.debian.org/security/2005/dsa-664</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-02-04 04:15:04 0000</bug_when>
            <thetext>Ubuntu released one too:

http://www.ubuntulinux.org/support/documentation/usn/usn-75-1

Security please vote!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2005-02-04 04:21:22 0000</bug_when>
            <thetext>I slightly tend towards a GLSA, especially since Debian and Ubuntu published one and a CAN (CAN-1999-1572) exists too. Although it&apos;s not too big of a thing.
So maybe half a vote towards a GLSA ;-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2005-02-04 05:10:20 0000</bug_when>
            <thetext>I give 1/4 of a vote towards a GLSA.

So vorlon and I now have 3/4&apos;s of a real vote!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-02-04 08:50:47 0000</bug_when>
            <thetext>Let&apos;s consider that lewk+vorlon makes one YES, and my vote one NO. jaervosz, you decide (after all, it&apos;s your draft).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-02-04 12:23:46 0000</bug_when>
            <thetext>I won&apos;t cast a vote here -&gt; closing without GLSA.

If anyone disagree feel free to reopen.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2005-02-06 18:38:03 0000</bug_when>
            <thetext>mips stable.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>