Summary: | dev-db/mysql: insecure temporary file creation | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Matthias Geerdsen (RETIRED) <vorlon> |
Component: | New packages | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | dberkholz, mysql-bugs |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://lists.debian.org/debian-security-announce/debian-security-announce-2004/msg00143.html | ||
Whiteboard: | A3 [glsa] jaervosz | ||
Package list: | Runtime testing required: | --- |
Description
Matthias Geerdsen (RETIRED)
2004-08-18 01:20:07 UTC
mysql-bugs please provide an updated ebuild. in cvs now. 3.23.58-r1 4.0.20-r1 Arches please mark stable. Target keywords: 3.23.58-r1 alpha hppa ppc sparc x86 4.0.20-r1 alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sparc x86 Package maintainers, is it possible to test a test case or two that would show this is indeed fixed? Security, sorry for sounding like a broken record ;) weeve: I don't even know anybody that uses the affected utility, much less be able to produce a halfway usable testcase for it. This is one of the times I'd say that so long as the fixed code is in the mysqlhotcopy script, I'd have to leave it at that. masked stable on ppc. 3.23.58-r1 & 4.0.20-r1 sparc stable. The test case can be done in a simple way, use mysqlhotcopy to copy (sic) a big db, so as to have time to kill the process and check the resulting non-cleaned up temporary file it uses. Otherwise you can play with an strace, but it's a torture. Stable on mips Stable on alpha. moved to stable for arm/hppa/amd64/ia64 ***bump*** Arches please mark stable ***bump*** done on x86. GLSA 200409-02 ppc64, s390 : please mark mysql-4.0.20-r1 stable to benefit from that GLSA. fixed on ppc64 |