Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 22972
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Daniel Ahlberg (RETIRED) <aliz@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 22972 depends on: Show dependency tree
Bug 22972 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2003-06-17 00:47 0000
[SECURITY] [DSA-323-1] New noweb packages fix insecure temporary file creation 
 
From:  
Matt Zimmerman <mdz@debian.org> 
 
 
To:  
debian-security-announce@lists.debian.org 
 
 
Date:  
Today 04.07.00 
 
 
 
Message was signed with unknown key 0x43E25D1E. 
The validity of the signature cannot be verified. 
 
 
-------------------------------------------------------------------------- 
Debian Security Advisory DSA 323-1                     security@debian.org 
http://www.debian.org/security/                             Matt Zimmerman 
June 16th, 2003                         http://www.debian.org/security/faq 
-------------------------------------------------------------------------- 
 
Package        : noweb 
Vulnerability  : insecure temporary files 
Problem-Type   : local 
Debian-specific: no 
CVE Id         : CAN-2003-0381 
 
Jakob Lell discovered a bug in the 'noroff' script included in noweb 
whereby a temporary file was created insecurely.  During a review, 
several other instances of this problem were found and fixed.  Any of 
these bugs could be exploited by a local user to overwrite arbitrary 
files owned by the user invoking the script.

------- Comment #1 From Daniel Ahlberg (RETIRED) 2003-06-28 13:52:19 0000 -------
glsa sent 

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug