Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 97187 - app-mobilephone/sms <= 1.9.2m insecure tmp file creation
Summary: app-mobilephone/sms <= 1.9.2m insecure tmp file creation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor
Assignee: Gentoo Security
URL:
Whiteboard: C3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-06-27 04:14 UTC by Romang
Modified: 2005-07-14 04:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Romang 2005-06-27 04:14:58 UTC
Hello,

Take a look on

contrib/miastoplusa/mpl.sh

9 cat >/tmp/request1 << __ENDME__
27 cat >/tmp/request2 <<__ENDME2__
48 nc www.miastoplusa.pl 80 < /tmp/request1
54 nc www.miastoplusa.pl 80 < /tmp/request2

This contrib file is installed by portage

>>> /usr/share/doc/sms-1.9.2m/contrib/miastoplusa/mpl.sh

Regards.
Comment 1 Tavis Ormandy (RETIRED) gentoo-dev 2005-07-05 06:25:39 UTC
confirmed, although very low risk..it's only installed in docdir, and seems to 
be for a polish telecom website.

suggest adding set -C before , and rm -f after.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-07-11 05:21:55 UTC
Eric, please tell us when upstream is aware.
Comment 3 Romang 2005-07-12 00:50:36 UTC
Hello,

Upstream notified.

Regards.
Comment 4 Romang 2005-07-12 01:45:21 UTC
Hello,

Response from upstream :

It's very old version. It was released almost year ago - 21st august 
2004. Current version - 2.0.3 does not contain vulnerable file.

REgards.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-07-12 01:45:46 UTC
According to upstream, 2.0.3 does not include the vulnerable file.
We should probably mark stable this version and call it a day.

dragonheart / tester : please bump 2.0.3 to x86 stable
We'll wait for public disclosure to open this one.
Comment 6 Daniel Black (RETIRED) gentoo-dev 2005-07-13 05:19:21 UTC
Jeremy - any objectsion to x86 and ppc for dev-libs/pcre++? works for me (on 
both)? 
 
  RDEPEND.bad                    2 
   app-mobilephone/sms/sms-2.0.3.ebuild: ppc(default-linux/ppc/2005.0) 
['dev-libs/pcre++'] 
   app-mobilephone/sms/sms-2.0.3.ebuild: x86(default-linux/x86/2005.0) 
['dev-libs/pcre++'] 
 
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-07-13 12:55:16 UTC
Leaked by Secunia, SA16038
Comment 8 Daniel Black (RETIRED) gentoo-dev 2005-07-13 15:10:48 UTC
Jeremy - I took a risk an just made pcre++ stable - no outstanding bugs in a 
year. 
 
sms<=1.9.2m removed and 2.0.3 ppc and x86 stable. 
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-07-14 02:04:49 UTC
Voting for GLSA. This is a contrib script, not in path -> I vote NO
Comment 10 Tavis Ormandy (RETIRED) gentoo-dev 2005-07-14 04:45:44 UTC
agreed, NO.
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-07-14 04:50:51 UTC
Reopen if you disagree