Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 104878 - ncompress <= 4.2.4 insecure temporary file creation
Summary: ncompress <= 4.2.4 insecure temporary file creation
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-05 04:07 UTC by Romang
Modified: 2005-09-16 07:46 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Romang 2005-09-05 04:07:31 UTC
#########################################################

ncompress insecure temporary file creation

Vendor: ftp://ftp.leo.org/pub/comp/os/unix/linux/sunsite/utils/compress/
Advisory: http://www.zataz.net/adviso/ncompress-09052005.txt
Vendor informed: yes
Exploit available: yes
Impact : low
Exploitation : low

#########################################################

The vulnerability is caused due to temporary file being created insecurely.
This can be exploited via symlink attacks in combination with a race 
condition to create and overwrite arbitrary files
with the privileges of the user running the affected script.

##########
Versions:
##########

ncompress <= 4.2.4-r1

##########
Solution:
##########

Use the gzip zdiff and zcmp

#########
Timeline:
#########

Vendor notified : 2005-09-05

#####################
Technical details :
#####################

ncompress use vulnerable version off zdiff and zcmp.

#########
Related :
#########

Secunia : http://secunia.com/advisories/13131/
CVE : CAN-2004-0970
Comment 1 Tavis Ormandy (RETIRED) gentoo-dev 2005-09-05 04:21:53 UTC
doesnt affect us, marking INVALID.
Comment 2 Tavis Ormandy (RETIRED) gentoo-dev 2005-09-16 07:46:43 UTC
public, opening.