Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 386351 (CVE-2010-0318) - <sys-freebsd/freebsd-sources-{7.2-r3,8.0}: multiple vulnerabilities (CVE-2010-0318,CVE-2011-1739)
Summary: <sys-freebsd/freebsd-sources-{7.2-r3,8.0}: multiple vulnerabilities (CVE-2010...
Status: RESOLVED FIXED
Alias: CVE-2010-0318
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-08 15:04 UTC by GLSAMaker/CVETool Bot
Modified: 2011-12-08 23:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 15:04:53 UTC
CVE-2010-0318 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0318):
  The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and
  8.0, when creating files during replay of a setattr transaction, uses 7777
  permissions instead of the original permissions, which might allow local
  users to read or modify unauthorized files in opportunistic circumstances
  after a system crash or power failure.
Comment 1 Naohiro Aota gentoo-dev 2011-11-18 12:53:43 UTC
FYI: Upstream patch had already been applied to portage tree.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-11-18 23:13:12 UTC
Thank you, Naohiro. Do you know which version in portage was the first fixed?
Comment 3 Naohiro Aota gentoo-dev 2011-11-20 03:51:10 UTC
From ChangeLog:
> *freebsd-sources-8.0 (19 Mar 2010)
>
>  19 Mar 2010; Alexis Ballier <aballier@gentoo.org>
>  +freebsd-sources-8.0.ebuild, +files/freebsd-sources-8.0-gentoo.patch,
>  +files/freebsd-sources-8.0-sparc64.patch,
>  +files/freebsd-sources-8.0-subnet-route-pr40133.patch,
>  +files/freebsd-sources-8.0-werror.patch,
>  +files/freebsd-sources-8.0-zfs.patch:
>  bump to 8.0 from the bsd overlay

> *freebsd-sources-7.2-r3 (09 Jan 2010)
> 
>   09 Jan 2010; Alexis Ballier <aballier@gentoo.org>
>   +freebsd-sources-7.2-r3.ebuild, +files/freebsd-sources-7.2-zfs712.patch:
>   add patch for FreeBSD-SA-10:03.zfs

freebsd-sources-7.2-r3 and freebsd-sources-8.0 include the fix.
Comment 4 Tim Sammut (RETIRED) gentoo-dev 2011-12-08 23:51:13 UTC
Great, thank you. Closing noglsa.