| Summary: | app-arch/unzip TOCTOU issue (CVE-2005-2475) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Sune Kloppenborg Jeppesen (RETIRED) <jaervosz> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED INVALID | ||
| Severity: | normal | ||
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://www.securityfocus.com/archive/1/407065/30/0/threaded | ||
| Whiteboard: | |||
| Package list: | Runtime testing required: | --- | |
|
Description
Sune Kloppenborg Jeppesen (RETIRED)
2005-08-02 10:40:35 UTC
Oh well what a nice bug number, let's close this as invalid and pretend nothing happened. (In reply to comment #1) > Oh well what a nice bug number, let's close this as invalid and pretend > nothing happened. Hm, why? Doesn't look like the issue is fixed. Debian did in DSA 903-1 and issued a regression fix (DSA 903-2) Carlo: we consider this is a ridiculous security issue, highly questionable whether we even consider this a bug, if the maintainer or upstream decides to fix it, that is fine, but we dont consider it worthy of attention from security team. Hm, yes seems reasonable. Just wanted to be sure, this didn't got missed. Sorry for the noise. |