Bug 177512 - www-client/elinks Untrusted search path (CVE-2007-2027)
|
Bug#:
177512
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: jaervosz@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2027
|
|
Summary: www-client/elinks Untrusted search path (CVE-2007-2027)
|
|
Keywords:
|
|
Status Whiteboard: B2 [glsa] jaervosz
|
|
Opened: 2007-05-07 16:13 0000
|
Untrusted search path vulnerability in the add_filename_to_string function in
intl/gettext/loadmsgcat.c for Elinks 0.11.1 adds "../po" to the search path for
.po files, which might allow local users to cause Elinks to use an untrusted
gettext message catalog, which can be leveraged to conduct format string
attacks.
*** Bug 177777 has been marked as a duplicate of this bug. ***
This is now fixed in CVS thanks to a patch pulled from the elinks GIT tree.
Thx Micheal.
Could you make a revbump of the latest stable so users can use glsa-check to
upgrade and arches have a chance to test?
Woops didn't mean to CC arches already. Sorry for the noise.
Done, 0.11.2-r1 is in CVS now.
Jaervosz, seems it's ok for calling arches this time :)
Thx for the reminder:-)
Arches please test and mark stable. Target keywords are:
elinks-0.11.2-r1.ebuild:KEYWORDS="alpha amd64 hppa mips ppc ppc64 sparc x86
~x86-fbsd"
GLS 200706-03, thanks everybody!
mips don't forget to mark stable to befenit from the glsa