Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 552622 - <sys-process/parallel-20150522: Insecure temporary files (CVE-2015-{4155,4156})
Summary: <sys-process/parallel-20150522: Insecure temporary files (CVE-2015-{4155,4156})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-20 12:47 UTC by GLSAMaker/CVETool Bot
Modified: 2015-06-30 19:08 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2015-06-20 12:47:19 UTC
CVE-2015-4156 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4156):
  GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo
  with --sshlogin, allows local users to write to arbitrary files via a
  symlink attack on a temporary file.

CVE-2015-4155 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4155):
  GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat,
  (4) --fifo, or (5) --compress, allows local users to write to arbitrary
  files via a symlink attack on a temporary file.


Maintainers: if this package is ready for stabilization, please CC arch teams.
Comment 1 Ian Delaney (RETIRED) gentoo-dev 2015-06-25 06:34:33 UTC
Keywords for sys-process/parallel:
         |                               | u   |  
         | a a   a         n   p     s   | n   |  
         | l m   r h i m m i   p s   p   | u s | r
         | p d a m p a 6 i o p c 3   a x | s l | e
         | h 6 r 6 p 6 8 p s p 6 9 s r 8 | e o | p
         | a 4 m 4 a 4 k s 2 c 4 0 h c 6 | d t | o
---------+-------------------------------+-----+-------
20140622 | o + o o o o o o o o o o o o + | o 0 | gentoo
20141122 | o + o o o o o o o o o o o o ~ | o   | gentoo
20150122 | o ~ o o o o o o o o o o o o ~ | #   | gentoo

Arches please proceed with sys-process/parallel-20150522.
Comment 2 Agostino Sarubbo gentoo-dev 2015-06-26 08:32:03 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2015-06-26 08:32:17 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 4 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-06-27 12:44:31 UTC
GLSA vote: No.
Comment 5 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-06-30 13:45:26 UTC
GLSA Vote: No
Comment 6 Ian Delaney (RETIRED) gentoo-dev 2015-06-30 13:54:52 UTC
  30 Jun 2015; Ian Delaney <idella4@gentoo.org> -parallel-20140622.ebuild,
  -parallel-20141122.ebuild, -parallel-20150122.ebuild,
  -parallel-20150222.ebuild, -parallel-20150322.ebuild:
  cleanup for bug #552622