Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 24001 - media-gfx/mediamagick
Summary: media-gfx/mediamagick
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords: SECURITY
Depends on:
Blocks:
 
Reported: 2003-07-06 13:42 UTC by Daniel Ahlberg (RETIRED)
Modified: 2019-11-03 12:30 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-07-06 13:42:13 UTC
-------------------------------------------------------------------------- 
Debian Security Advisory DSA 331-1                     security@debian.org 
http://www.debian.org/security/                             Matt Zimmerman 
June 27th, 2003                          http://www.debian.org/security/faq 
-------------------------------------------------------------------------- 
 
Package        : imagemagick 
Vulnerability  : insecure temporary file 
Problem-Type   : local 
Debian-specific: no 
CVE Ids        : CAN-2003-0455 
 
imagemagick's libmagick library, under certain circumstances, creates 
temporary files without taking appropriate security precautions.  This 
vulnerability could be exploited by a local user to create or 
overwrite files with the privileges of another user who is invoking a 
program using this library.
Comment 1 Andrew Cooks (RETIRED) gentoo-dev 2004-01-18 04:58:36 UTC
There were many changes to imagemagick in the last few months, but I can't figure out whether this bug received any attention and if it's still an issue.

In the mean time, it seems like mediamagick disapeared again and imagemagick was revived.

Imagemagick 5.5.8 was released but I didn't see anything about the bug in the changelog.

The current stable version in gentoo is 5.5.6-r1.

What happen?

Can we (actually not me) bump the version and pretend we (I suppose you) don't know anything about this bug?
Comment 2 SpanKY gentoo-dev 2004-02-11 21:10:32 UTC
the error is in TemporaryFilename() which should be fixed in all 5.5.7.x releases (i verified only 5.5.7.15)

i've bumped that version to stable for all archs (x86 ppc sparc alpha hppa) ... i only have x86/ppc/hppa so i cant vouch for sparc/alpha, but i dont see any bug reports in bugzilla about imagemagick that indicate problems :P
Comment 3 Aida Escriva-Sammer (RETIRED) gentoo-dev 2004-03-24 07:32:07 UTC
Once someone tests 5.5.7.15 ebuild on mips, 5.5.6-r1 and earlier need to be removed. 
Comment 4 Kurt Lieber (RETIRED) gentoo-dev 2004-03-30 01:08:28 UTC
this bug is fixed on all supported architectures.  closing.