Bug 78634 - dev-perl/DBI CAN-2005-0077 Insecure temporary files
|
Bug#:
78634
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: All
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: jaervosz@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
http://archives.neohapsis.com/archives/fulldisclosure/2005-01/0721.html
|
|
Summary: dev-perl/DBI CAN-2005-0077 Insecure temporary files
|
|
Keywords:
|
|
Status Whiteboard: A3 [glsa] jaervosz
|
|
Opened: 2005-01-19 00:56 0000
|
Javier Fernández-Sanguino Peña from the Debian Security Audit Project
discovered that the DBI library, the Perl5 database interface, creates
a tmporary file in an insecure manner. This can be exploited by a
malicious user to overwrite arbitrary files owned by the person
executing the program.
No upstream patch yet. Will attach Debian workaround patch later if needed.
Patch looks to apply cleanly on all versions in dev-perl. Just give me the word
and we can roll this out.
Micheal please attach the updated ebuild to this bug and we will call needed
arch testers individually.
two revision posted (based on KEYWORDing). 1.46 went into the tree as a new
copy from upstream a few minutes ago (the two attached are in no way in portage
atm).
This is public now. Micheal please commit the updated ebuild.
GLSA should probably be grouped with bug 75696 (both Perl, both tmpfile vulns).
Michael, could you please bump on dev-perl/perl side too ?