Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 69665 - CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
Summary: CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-31 13:24 UTC by Robert Muchacki (RETIRED)
Modified: 2004-11-01 04:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Muchacki (RETIRED) gentoo-dev 2004-10-31 13:24:55 UTC
CatDoc XLSView Local Insecure Temporary File Creation Vulnerability.

It affects version 0.91.5. The latest version in portage tree is 0.93.3.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-10-31 13:31:49 UTC
Robert more information is needed to accept the bug. Perhaps you forgot to include a link?
Comment 2 Robert Muchacki (RETIRED) gentoo-dev 2004-10-31 13:43:48 UTC
Yes, sorry :) To much work ;]

http://www.securityfocus.com/bid/11560/discussion/

If I find anything more, I'll come up with it.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-10-31 14:04:15 UTC
text-markup this seems like an old bug please verify if catdoc-0.93.3 is also vulnerable.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2004-11-01 04:11:38 UTC
This affects an msxlsview.sh or xlsview. Our 0.93.3 doesn't install any such script file. And Debian did only patch their 0.91.5 and not the recent 0.93.x.

So I guess we can say we're not affected. Please reopen this bug if you have further evidence I may have missed.