Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 247479 (CVE-2008-5151)

Summary: sci-visualization/mayavi symlink attack (CVE-2008-5151)
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: normal CC: sci
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5151
Whiteboard: ~3 [ebuild]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 235770    

Description Stefan Behte (RETIRED) gentoo-dev Security 2008-11-18 19:04:16 UTC
CVE-2008-5151 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5151):
  test_parser.py in mayavi 1.5 allows local users to overwrite
  arbitrary files via a symlink attack on the /tmp/err.log temporary
  file.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 16:24:32 UTC
*PING*
Comment 2 Sébastien Fabbro (RETIRED) gentoo-dev 2008-12-03 15:17:26 UTC
Hi,

I think this advisory doesn't apply. The /tmp/err.log attack is on a comment in test_parser.py, and looking at the code, the only reference to a possible temp file was commented out (line 161).
So I would close this as invalid but I need security experts to confirm.

Thanks
Comment 3 Sébastien Fabbro (RETIRED) gentoo-dev 2009-01-19 22:53:07 UTC
We should close this one, as it is a non issue.
@security: ok with that?
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-20 00:15:46 UTC
Confirmed, closing.