Summary: | sys-apps/gzip | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Daniel Ahlberg (RETIRED) <aliz> |
Component: | New packages | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | critical | CC: | solar |
Priority: | Highest | ||
Version: | 1.0 | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Daniel Ahlberg (RETIRED)
![]() # emerge -pv gzip [ebuild R ] sys-apps/gzip-1.3.3-r1 +nls -build # strace -ff -eopen znew open("/tmp/zfoo.21403.1", O_WRONLY|O_CREAT|O_EXCL|O_LARGEFILE, 0666) = 3 open("/tmp/zfoo.21403.2", O_WRONLY|O_CREAT|O_EXCL|O_LARGEFILE, 0666) = 3 At a quick glance we do seem vuln to this problem. I didnt check gzexe and am unaware if its has the same problems outlined in debs announcement. Anyway patches should be made and a GLSA should go out ASAP. glsa sent |