Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 102577
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 102577 depends on: Show dependency tree
Bug 102577 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-08-14 22:24 0000
-----BEGIN PGP SIGNED MESSAGE----- 
Hash: SHA1 
 
 
KDE Security Advisory: langen2kvtml tempfile vulnerability 
Original Release Date: 2008-08-15 
URL: http://www.kde.org/info/security/advisory-20050815-1.txt 
 
0. References 
 
        CAN-2005-2101 
 
1. Systems affected: 
 
        All KDE releases starting from KDE 3.0 up to including 
        KDE 3.4.2. 
 
 
2. Overview: 
 
        Ben Burton notified the KDE security team about several 
        tempfile handling related vulnerabilities in langen2kvtml, 
        a conversion script for kvoctrain. This vulnerability was 
        initially discovered by Javier Fern

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-08-14 22:24:20 0000 -------
-----BEGIN PGP SIGNED MESSAGE----- 
Hash: SHA1 
 
 
KDE Security Advisory: langen2kvtml tempfile vulnerability 
Original Release Date: 2008-08-15 
URL: http://www.kde.org/info/security/advisory-20050815-1.txt 
 
0. References 
 
        CAN-2005-2101 
 
1. Systems affected: 
 
        All KDE releases starting from KDE 3.0 up to including 
        KDE 3.4.2. 
 
 
2. Overview: 
 
        Ben Burton notified the KDE security team about several 
        tempfile handling related vulnerabilities in langen2kvtml, 
        a conversion script for kvoctrain. This vulnerability was 
        initially discovered by Javier Fernández-Sanguino Peña. 
 
        The script uses known filenames in /tmp which allow an 
        local attacker to overwrite files writeable by the 
        user (manually) invoking the conversion script. 
 
3. Impact: 
 
        A local file can overwrite files and possibly elevate 
        privileges. 
 
 
4. Solution: 
 
        Source code patches have been made available which fix these 
        vulnerabilities. Contact your OS vendor / binary package provider 
        for information about how to obtain updated binary packages. 
 
 
5. Patch: 
 
        Patch for KDE 3.4.2 is available from  
        ftp://ftp.kde.org/pub/kde/security_patches : 
 
        0e82c5810df3b04370188ba13cc50203  post-3.4.2-kdeedu.diff 
 
 
-----BEGIN PGP SIGNATURE----- 
Version: GnuPG v1.4.2 (GNU/Linux) 
 
iD8DBQFC/+ZevsXr+iuy1UoRAh0PAJ9Lun/gca6T+oY5LPmJRDa7vOY41wCeNJY5 
D2fO/2ZNBXZzwiCDJLBnIBM= 
=uz8a 
-----END PGP SIGNATURE-----

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-08-14 22:27:31 0000 -------
Arches please test and mark stable: 
 
kdeedu-3.3.2-r2.ebuild 
kdeedu-3.4.1-r1.ebuild 
kvoctrain-3.4.1-r1.ebuild 

------- Comment #3 From Markus Rothe 2005-08-15 05:44:38 0000 -------
stable on ppc64

------- Comment #4 From Jose Luis Rivero (yoswink) 2005-08-15 05:57:37 0000 -------
kdeedu-3.3.2-r2 marked stable on alpha.

------- Comment #5 From Michael Hanselmann (hansmi) (RETIRED) 2005-08-15 06:10:41 0000 -------
Stable on ppc.

------- Comment #6 From Michael Hanselmann (hansmi) (RETIRED) 2005-08-15 06:16:15 0000 -------
Stable on hppa.

------- Comment #7 From Luis Medinas (RETIRED) 2005-08-15 07:12:31 0000 -------
Stable on AMD64.

------- Comment #8 From Jason Wever (RETIRED) 2005-08-15 19:56:14 0000 -------
SPARC'd 

------- Comment #9 From Sune Kloppenborg Jeppesen 2005-08-15 22:21:04 0000 -------
This one is ready for GLSA decision. I tend to vote NO assuming that the 
script is not run automatically. 

------- Comment #10 From Bryan Østergaard (RETIRED) 2005-08-16 02:26:50 0000 -------
ia64 stable.

------- Comment #11 From Tim Yamin (RETIRED) 2005-08-16 08:34:05 0000 -------
Vote no.

------- Comment #12 From Sune Kloppenborg Jeppesen 2005-08-16 08:46:52 0000 -------
Reverting my vote to full NO and closing. 

------- Comment #13 From Thierry Carrez (RETIRED) 2005-08-18 09:40:45 0000 -------
*** Bug 102151 has been marked as a duplicate of this bug. ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug