Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 104878

Summary: ncompress <= 4.2.4 insecure temporary file creation
Product: Gentoo Security Reporter: Romang <zataz>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: minor    
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Romang 2005-09-05 04:07:31 UTC
#########################################################

ncompress insecure temporary file creation

Vendor: ftp://ftp.leo.org/pub/comp/os/unix/linux/sunsite/utils/compress/
Advisory: http://www.zataz.net/adviso/ncompress-09052005.txt
Vendor informed: yes
Exploit available: yes
Impact : low
Exploitation : low

#########################################################

The vulnerability is caused due to temporary file being created insecurely.
This can be exploited via symlink attacks in combination with a race 
condition to create and overwrite arbitrary files
with the privileges of the user running the affected script.

##########
Versions:
##########

ncompress <= 4.2.4-r1

##########
Solution:
##########

Use the gzip zdiff and zcmp

#########
Timeline:
#########

Vendor notified : 2005-09-05

#####################
Technical details :
#####################

ncompress use vulnerable version off zdiff and zcmp.

#########
Related :
#########

Secunia : http://secunia.com/advisories/13131/
CVE : CAN-2004-0970
Comment 1 Tavis Ormandy (RETIRED) gentoo-dev 2005-09-05 04:21:53 UTC
doesnt affect us, marking INVALID.
Comment 2 Tavis Ormandy (RETIRED) gentoo-dev 2005-09-16 07:46:43 UTC
public, opening.