Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 257012 (CVE-2009-0318) - <app-office/gnumeric-1.8.4-r1 Untrusted search path vulnerability (CVE-2009-0318)
Summary: <app-office/gnumeric-1.8.4-r1 Untrusted search path vulnerability (CVE-2009-0...
Status: RESOLVED FIXED
Alias: CVE-2009-0318
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [glsa]
Keywords:
Depends on: CVE-2008-5983
Blocks:
  Show dependency tree
 
Reported: 2009-01-30 22:56 UTC by Stefan Behte (RETIRED)
Modified: 2009-04-03 13:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-01-30 22:56:24 UTC
CVE-2009-0318 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0318):
  Untrusted search path vulnerability in the GObject Python interpreter
  wrapper in Gnumeric allows local users to execute arbitrary code via
  a Trojan horse Python file in the current working directory, related
  to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-01-30 23:40:55 UTC
I am not sure whether this bug is being tracked upstream. Please see the blocker for details and a patch example.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-03-04 17:11:18 UTC
ping
Comment 3 Gilles Dartiguelongue (RETIRED) gentoo-dev 2009-03-09 22:46:22 UTC
Commited as 1.8.4-r1. Sorry for taking so long.
Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-03-10 07:24:18 UTC
Arches, please test and mark stable:
=app-office/gnumeric-1.8.4-r1
Target keywords : "alpha amd64 hppa ia64 ppc ppc64 sparc x86"
Comment 5 Ferris McCormick (RETIRED) gentoo-dev 2009-03-10 15:59:05 UTC
Sparc stable for gnumeric-1.8.4-r1.  Note that this does not match the summary.
Comment 6 Ferris McCormick (RETIRED) gentoo-dev 2009-03-10 16:02:21 UTC
(In reply to comment #5)
> Sparc stable for gnumeric-1.8.4-r1.  Note that this does not match the summary.
> 

Ah, I see the summary was updated.  Ignore the comments.
Comment 7 Brent Baude (RETIRED) gentoo-dev 2009-03-11 15:00:51 UTC
ppc64 done
Comment 8 Tobias Klausmann (RETIRED) gentoo-dev 2009-03-11 19:29:43 UTC
Stable on alpha.
Comment 9 Markus Meier gentoo-dev 2009-03-15 01:37:39 UTC
!!! dodoc: TODO does not exist
>>> Completed installing gnumeric-1.8.4-r1 into /var/tmp/portage/app-office/gnumeric-1.8.4-r1/image/
Comment 10 Markus Meier gentoo-dev 2009-03-15 02:18:29 UTC
amd64/x86 stable
Comment 11 Raúl Porcel (RETIRED) gentoo-dev 2009-03-15 19:11:53 UTC
ia64 stable
Comment 12 Brent Baude (RETIRED) gentoo-dev 2009-03-18 22:15:04 UTC
ppc done
Comment 13 Jeroen Roovers (RETIRED) gentoo-dev 2009-03-23 05:17:52 UTC
Stable for HPPA.
Comment 14 Robert Buchholz (RETIRED) gentoo-dev 2009-04-03 13:51:45 UTC
GLSA 200904-03