Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 249395 (CVE-2008-5145) - app-benchmarks/ltp<=20081031 symlink attack (CVE-2008-5145)
Summary: app-benchmarks/ltp<=20081031 symlink attack (CVE-2008-5145)
Status: RESOLVED FIXED
Alias: CVE-2008-5145
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-11-30 15:31 UTC by Stefan Behte (RETIRED)
Modified: 2008-12-04 23:23 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 15:31:38 UTC
CVE-2008-5145 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5145):
  ltpmenu in ltp 20060918 allows local users to overwrite arbitrary
  files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary
  file.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 15:36:38 UTC
grep -i "/tmp/" ./ltp-full-20081031/ltpmenu | grep -e rm -e ">"
    rm -f /tmp/runltp.*
                which $cmd &>/tmp/runltp.err.$$ ;
                      2>/tmp/runltp.results.$$ || RC=$?
                          2>/tmp/runltp.outdir.$$ ;
                  2>/tmp/runltp.interval.$$ ;
                          2>/tmp/runltp.length.$$ ;
            2>/tmp/runltp.choice.$$ || RC=$?
                   >> /tmp/runltp.test.list.$$ ;
                                  2>/tmp/runltp.out.$$ ;
                        2>/tmp/runltp.out.$$ ;
                2>/tmp/runltp.scenario.$$ || RC=$?
                  2>/tmp/runltp.mainmenu.$$ || RC=$?

As it's already hardmasked, it might be ok to just add a hint in package.mask and close this?
Comment 2 Patrick Lauer gentoo-dev 2008-12-04 22:04:34 UTC
Will have a look really soon now.
Comment 3 Patrick Lauer gentoo-dev 2008-12-04 22:33:48 UTC
Punted old version.
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2008-12-04 23:23:21 UTC
Punted? What do you mean?!