Summary: | app-emulation/xen-tools: audit wrt insecure temp file usage | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Christian Hoffmann (RETIRED) <hoffie> |
Component: | Auditing | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | normal | CC: | craig |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
URL: | http://bugs.debian.org/496367 | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 235770 |
Description
Christian Hoffmann (RETIRED)
2008-08-26 17:26:31 UTC
This bug should have been filed as UNCONFIRMED. I'm unable to find the offending file in xen-tools and I'm unable to emerge xen itself (sed: -e expression #6, char 930: unterminated `s' command). Might be related to the fact that I emerged it with --nodeps. rbu, can you check? You're maintainer anyway :p The xen-tools package contains the file ( /tools/ioemu/target-i386-dm/qemu-dm.debug ), and that indeed creates those files insecurely. However, neither the Makefiles not the ebuilds install this file. *** Bug 246068 has been marked as a duplicate of this bug. *** |