Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 101773 - app-emulation/wine: Insecure Temporary File Creation
Summary: app-emulation/wine: Insecure Temporary File Creation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://secunia.com/advisories/16352/
Whiteboard: C3 [noglsa] formula7
Keywords:
: 101772 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-08-08 10:45 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-08-24 07:45 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-08-08 10:45:02 UTC
Description:
Javier Fernandez-Sanguino Pena has reported a vulnerability in wine, which can
be exploited by malicious, local users to perform certain actions on a
vulnerable system with escalated privileges.

The vulnerability is caused due to a temporary file being created insecurely in
"/tmp" by winelauncher.in under certain error conditions. This can be exploited
via symlink attacks to create or overwrite arbitrary files with the privileges
of the user running the affected application.

The vulnerability has been reported in version 20050725. Other versions may also
be affected.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2005-08-08 11:01:58 UTC
*** Bug 101772 has been marked as a duplicate of this bug. ***
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-08-21 08:10:40 UTC
Patch at :
http://cvs.winehq.org/cvsweb/wine/programs/winelauncher.in.diff?r1=1.4&r2=1.5

Wine herd: please bump with patch (or advise)
Comment 3 SpanKY gentoo-dev 2005-08-22 18:13:33 UTC
added patch to cvs and to all applicable wine ebuilds ... not sure how security
wants to handle this (revbumping all ebuilds/etc...)
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-08-23 00:45:32 UTC
You should revbump latest stable and unstable:
20050111-r1 -> 20050111-r2
20050725 -> 20050725-r1
Comment 5 SpanKY gentoo-dev 2005-08-23 17:19:18 UTC
done
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-08-24 00:35:00 UTC
Ready for GLSA vote. "Under certain error conditions", so I tend to vote NO
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-24 02:14:32 UTC
I vote NO. 
Comment 8 Jean-François Brunette (RETIRED) gentoo-dev 2005-08-24 07:45:20 UTC
Two votes for 'No GLSA' so closing without GLSA.