Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 87939 - app-arch/sharutils: Insecure tempfile creation
Summary: app-arch/sharutils: Insecure tempfile creation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: A3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-04-04 11:33 UTC by Luke Macken (RETIRED)
Modified: 2005-04-06 16:10 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Luke Macken (RETIRED) gentoo-dev 2005-04-04 11:33:15 UTC
Details follow:

Joey Hess discovered that "unshar" created temporary files in an
insecure manner. This could allow a symbolic link attack to create or
overwrite arbitrary files with the privileges of the user invoking the
program.
Comment 1 Luke Macken (RETIRED) gentoo-dev 2005-04-04 11:35:44 UTC
Debian/ubuntu patch:

http://security.ubuntu.com/ubuntu/pool/main/s/sharutils/sharutils_4.2.1-10ubuntu0.2.diff.gz
Comment 2 SpanKY gentoo-dev 2005-04-04 20:49:15 UTC
4.2.1-r11 now in portage with the relevant parts of the ubuntu patch
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-04-05 00:40:04 UTC
Arches, please test and mark stable 4.2.1-r11
Comment 4 Markus Rothe (RETIRED) gentoo-dev 2005-04-05 07:40:56 UTC
stable on ppc64
Comment 5 Olivier Crete (RETIRED) gentoo-dev 2005-04-05 07:58:56 UTC
x86 done
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-04-05 08:04:53 UTC
Stable on ppc.
Comment 7 Gustavo Zacarias (RETIRED) gentoo-dev 2005-04-05 08:20:47 UTC
sparc stable.
Comment 8 Hardave Riar (RETIRED) gentoo-dev 2005-04-05 10:17:21 UTC
Stable on mips.
Comment 9 Bryan Østergaard (RETIRED) gentoo-dev 2005-04-06 01:36:40 UTC
Stable on alpha.
Comment 10 Jan Brinkmann (RETIRED) gentoo-dev 2005-04-06 12:34:56 UTC
  05 Apr 2005; Jan Brinkmann <luckyduck@gentoo.org>
  sharutils-4.2.1-r11.ebuild:
  Stable on amd64, bug #87939.
Comment 11 René Nussbaumer (RETIRED) gentoo-dev 2005-04-06 13:56:36 UTC
hansmi has marked this package stable.
Comment 12 Luke Macken (RETIRED) gentoo-dev 2005-04-06 15:16:59 UTC
GLSA 200504-06

arm/ia64/s390, please mark stable to benefit from GLSA.