Summary: | app-forensics/rkhunter Insecure temp file creation | ||||||
---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Sune Kloppenborg Jeppesen (RETIRED) <jaervosz> | ||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | normal | CC: | ka0ttic, michael | ||||
Priority: | High | ||||||
Version: | unspecified | ||||||
Hardware: | All | ||||||
OS: | All | ||||||
Whiteboard: | B3 [glsa] jaervosz | ||||||
Package list: | Runtime testing required: | --- | |||||
Attachments: |
|
Description
Sune Kloppenborg Jeppesen (RETIRED)
2005-04-21 22:50:00 UTC
Confirmed, there are more in rkhunter: /tmp/procmail.txt /tmp/proftpd.txt /tmp/openssh.txt these are UUoC as well, i suppose author didnt know 2>&1 :) Upstream notified. Upstream responded that he will look into it. upstream CC'ed. Created attachment 57197 [details, diff]
suggested fix
Looks good here. 1.2.3-r1 is in CVS pending new upstream release. CC'd archs please mark stable. Opening the bug since the fix is incvs now sparc stable. stable on amd64 Stable on ppc. New upstream release is out, but still vulnerable (none of the suggested fixes were applied). A patched 1.2.4 is in CVS. Looks like alpha stabled but never commented on the bug. This one's ready to go. GLSA 200504-25 |