Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 539794 - sys-apps/kexec-tools: insecure use of /tmp/*$$* filenames
Summary: sys-apps/kexec-tools: insecure use of /tmp/*$$* filenames
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [upstream/ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-11 16:22 UTC by Agostino Sarubbo
Modified: 2015-02-11 17:22 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-02-11 16:22:20 UTC
From ${URL} :

Harald Hoyer from Red Hat reported that /usr/lib/dracut/modules.d/99kdumpbase/module-setup.sh 
script uses insecure temporary files names, which can lead to a local denial of service.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Justin Lecher (RETIRED) gentoo-dev 2015-02-11 16:48:57 UTC
We are not installing this file. So not applicable to gentoo.