Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 66400 - sys-apps/ed-0.2-r3: mktemp vulnerability
Summary: sys-apps/ed-0.2-r3: mktemp vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa] koon
Keywords:
: 163220 (view as bug list)
Depends on: 73858
Blocks:
  Show dependency tree
 
Reported: 2004-10-05 03:17 UTC by Ulrich Müller
Modified: 2011-10-30 22:37 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
ed-0.2-mkstemp.patch (ed-0.2-mkstemp.patch,738 bytes, patch)
2004-10-05 03:19 UTC, Ulrich Müller
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Ulrich Müller gentoo-dev 2004-10-05 03:17:57 UTC
ed-0.2 use "mktemp" to create temporary files.
This problem is known since almost four years, see for example:
http://www.linuxsecurity.com/advisories/redhat_advisory-967.html

| The ed executable creates files in /tmp with predictable
| names. By using various symlink attacks, it is possible to
| have ed write to files it should not, change the permissions 
| of various files, etc.
Comment 1 Ulrich Müller gentoo-dev 2004-10-05 03:19:16 UTC
Created attachment 41133 [details, diff]
ed-0.2-mkstemp.patch

Patch from LFS.
Comment 2 Marc Vila 2004-10-05 03:34:09 UTC
seems like we install ed by default in gentoo, so this should be fixed.
also we don
Comment 3 Marc Vila 2004-10-05 03:34:09 UTC
seems like we install ed by default in gentoo, so this should be fixed.
also we don´t apply any kind of patch to fix this in our ed-0.2-r3
Comment 4 Ulrich Müller gentoo-dev 2004-10-05 04:26:17 UTC
Sorry, should of course have been ed-0.2-r3 in the subject.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2004-10-05 04:43:28 UTC
Base-system, please comment and/or apply patch.
Comment 6 SpanKY gentoo-dev 2004-10-05 06:00:04 UTC
0.2-r4 is in portage, lets make it stable
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2004-10-05 06:14:57 UTC
Arches, please test and mark sys-apps/ed-0.2-r4 stable :
Current KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sparc ~x86"
Target KEYWORDS="x86 ppc sparc mips alpha arm hppa amd64 ia64 ppc64 s390"
Comment 8 Bryan Østergaard (RETIRED) gentoo-dev 2004-10-05 07:45:48 UTC
Stable on alpha.
Comment 9 Olivier Crete (RETIRED) gentoo-dev 2004-10-05 10:43:22 UTC
Stable on x86
Comment 10 Gustavo Zacarias (RETIRED) gentoo-dev 2004-10-05 15:02:20 UTC
sparc tasty.
Comment 11 SpanKY gentoo-dev 2004-10-05 15:46:05 UTC
arm/hppa/ia64/s390 have been loved
Comment 12 Jochen Maes (RETIRED) gentoo-dev 2004-10-06 01:16:02 UTC
stable on ppc
Comment 13 Jeremy Huddleston (RETIRED) gentoo-dev 2004-10-07 14:45:25 UTC
stable amd64
Comment 14 SpanKY gentoo-dev 2004-10-07 18:45:07 UTC
mips stable
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2004-10-09 11:20:18 UTC
GLSA 200410-07
ppc64 : don't forget to mark stable to benefit from GLSA
Comment 16 Tom Gall (RETIRED) gentoo-dev 2004-10-09 20:07:02 UTC
stable on ppc64, thanks!
Comment 17 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2004-12-21 17:20:03 UTC
security: please see bug #73858. This security fix of yours has broken ed.
Comment 18 Thierry Carrez (RETIRED) gentoo-dev 2004-12-22 04:23:00 UTC
Well, it's not "our fix". vapier applied a patch (originally from LFS) on behalf of the base-system herd. But we can try to help in determining a more appropriate patch.
Comment 19 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-23 13:53:22 UTC
*** Bug 163220 has been marked as a duplicate of this bug. ***