Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 102577 - kde-base/kdeedu temp file vulnerability in langen2kvtml
Summary: kde-base/kdeedu temp file vulnerability in langen2kvtml
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.kde.org/info/security/advi...
Whiteboard: B3? [noglsa] jaervosz
Keywords:
: 102151 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-08-14 22:24 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-08-18 09:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-14 22:24:20 UTC
-----BEGIN PGP SIGNED MESSAGE----- 
Hash: SHA1 
 
 
KDE Security Advisory: langen2kvtml tempfile vulnerability 
Original Release Date: 2008-08-15 
URL: http://www.kde.org/info/security/advisory-20050815-1.txt 
 
0. References 
 
        CAN-2005-2101 
 
1. Systems affected: 
 
        All KDE releases starting from KDE 3.0 up to including 
        KDE 3.4.2. 
 
 
2. Overview: 
 
        Ben Burton notified the KDE security team about several 
        tempfile handling related vulnerabilities in langen2kvtml, 
        a conversion script for kvoctrain. This vulnerability was 
        initially discovered by Javier Fern
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-14 22:24:20 UTC
-----BEGIN PGP SIGNED MESSAGE----- 
Hash: SHA1 
 
 
KDE Security Advisory: langen2kvtml tempfile vulnerability 
Original Release Date: 2008-08-15 
URL: http://www.kde.org/info/security/advisory-20050815-1.txt 
 
0. References 
 
        CAN-2005-2101 
 
1. Systems affected: 
 
        All KDE releases starting from KDE 3.0 up to including 
        KDE 3.4.2. 
 
 
2. Overview: 
 
        Ben Burton notified the KDE security team about several 
        tempfile handling related vulnerabilities in langen2kvtml, 
        a conversion script for kvoctrain. This vulnerability was 
        initially discovered by Javier Fernández-Sanguino Peña. 
 
        The script uses known filenames in /tmp which allow an 
        local attacker to overwrite files writeable by the 
        user (manually) invoking the conversion script. 
 
3. Impact: 
 
        A local file can overwrite files and possibly elevate 
        privileges. 
 
 
4. Solution: 
 
        Source code patches have been made available which fix these 
        vulnerabilities. Contact your OS vendor / binary package provider 
        for information about how to obtain updated binary packages. 
 
 
5. Patch: 
 
        Patch for KDE 3.4.2 is available from  
        ftp://ftp.kde.org/pub/kde/security_patches : 
 
        0e82c5810df3b04370188ba13cc50203  post-3.4.2-kdeedu.diff 
 
 
-----BEGIN PGP SIGNATURE----- 
Version: GnuPG v1.4.2 (GNU/Linux) 
 
iD8DBQFC/+ZevsXr+iuy1UoRAh0PAJ9Lun/gca6T+oY5LPmJRDa7vOY41wCeNJY5 
D2fO/2ZNBXZzwiCDJLBnIBM= 
=uz8a 
-----END PGP SIGNATURE-----
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-14 22:27:31 UTC
Arches please test and mark stable: 
 
kdeedu-3.3.2-r2.ebuild 
kdeedu-3.4.1-r1.ebuild 
kvoctrain-3.4.1-r1.ebuild 
Comment 3 Markus Rothe (RETIRED) gentoo-dev 2005-08-15 05:44:38 UTC
stable on ppc64
Comment 4 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-08-15 05:57:37 UTC
kdeedu-3.3.2-r2 marked stable on alpha.
Comment 5 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-08-15 06:10:41 UTC
Stable on ppc.
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-08-15 06:16:15 UTC
Stable on hppa.
Comment 7 Luis Medinas (RETIRED) gentoo-dev 2005-08-15 07:12:31 UTC
Stable on AMD64.
Comment 8 Jason Wever (RETIRED) gentoo-dev 2005-08-15 19:56:14 UTC
SPARC'd 
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-15 22:21:04 UTC
This one is ready for GLSA decision. I tend to vote NO assuming that the 
script is not run automatically. 
Comment 10 Bryan Østergaard (RETIRED) gentoo-dev 2005-08-16 02:26:50 UTC
ia64 stable.
Comment 11 Tim Yamin (RETIRED) gentoo-dev 2005-08-16 08:34:05 UTC
Vote no.
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-08-16 08:46:52 UTC
Reverting my vote to full NO and closing. 
Comment 13 Thierry Carrez (RETIRED) gentoo-dev 2005-08-18 09:40:45 UTC
*** Bug 102151 has been marked as a duplicate of this bug. ***