First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 65647
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Alin Năstac <mrness@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 65647 depends on: Show dependency tree
Bug 65647 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-09-28 00:47 0000
Package name:           netpbm
 Advisory ID:            MDKSA-2004:011-1
 Date:                   September 27th, 2004
 Original Advisory Date: February 11th, 2004
 Affected versions:	 10.0, 9.2, Corporate Server 2.1,
			 Multi Network Firewall 8.2
 ______________________________________________________________________

 Problem Description:

 A number of temporary file bugs have been found in versions of NetPBM.
 These could allow a local user the ability to overwrite or create
 files as a different user who happens to run one of the the vulnerable
 utilities.

Update:

 The patch applied made some calls to the mktemp utility with an
 incorrect parameter which prevented mktemp from creating temporary
 files in some scripts.

------- Comment #1 From Sune Kloppenborg Jeppesen 2004-09-28 01:01:20 0000 -------
graphics please confirm and provide a fixed ebuild if necessary.

Mandrake Advisory here:

http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:011-1

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-09-29 22:21:54 0000 -------
Version 10 is unaffected by this. Graphics please patch 9.12 or advise which
version above 9.20 to mark stable.

------- Comment #3 From Philip Walls (RETIRED) 2004-09-30 07:03:55 0000 -------
Since 10.20 is already stable on amd64 and ppc64, can we try stablizing other
arches on this version? It's been around since February 2004

------- Comment #4 From Thierry Carrez (RETIRED) 2004-09-30 07:54:52 0000 -------
Yes I think we should have all arches mark a version (>=10.0) of their choice
stable, so that we can get rid of the last 9.x version. Most arches already
have.

Calling missing arches : hppa mips ppc sparc x86
Please test and mark 10.20 (or any other >=10 version) stable.

------- Comment #5 From Gustavo Zacarias (RETIRED) 2004-09-30 12:16:58 0000 -------
sparc stable.

------- Comment #6 From Jochen Maes (RETIRED) 2004-10-01 10:27:50 0000 -------
stable on ppc

------- Comment #7 From Jochen Maes (RETIRED) 2004-10-02 03:47:40 0000 -------
forgot to remove it :-)

------- Comment #8 From Olivier Crete 2004-10-02 14:29:39 0000 -------
10.20 stable on x86

------- Comment #9 From SpanKY 2004-10-02 21:58:04 0000 -------
hppa/ia64 stable

------- Comment #10 From Thierry Carrez (RETIRED) 2004-10-03 06:30:08 0000 -------
I'll draft the GLSA

------- Comment #11 From Thierry Carrez (RETIRED) 2004-10-04 10:33:41 0000 -------
GLSA 200410-02

First Last Prev Next    No search results available      Search page      Enter new bug