Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 107312 - app-arch/arc: insecure temporary file creation
Summary: app-arch/arc: insecure temporary file creation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-26 12:12 UTC by Carsten Lohrke (RETIRED)
Modified: 2005-10-04 05:56 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
proposed-fix.patch (proposed-fix.patch,1.06 KB, patch)
2005-09-26 12:13 UTC, Carsten Lohrke (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2005-09-26 12:12:14 UTC
http://www.zataz.net/adviso/arc-09052005.txt

arc is missing a maintainer and metadata.xml
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2005-09-26 12:13:50 UTC
Created attachment 69284 [details, diff]
proposed-fix.patch

Joey Schulze <joey@infodrom.org> replied on Bugtray proposing this patch.
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2005-09-26 12:15:15 UTC

*** This bug has been marked as a duplicate of 66251 ***
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2005-09-26 12:15:57 UTC
sorry, that one went wrong
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-09-27 00:32:07 UTC
vapier/solar: no maintainer, care to apply the patch ?
Comment 5 SpanKY gentoo-dev 2005-09-29 14:38:07 UTC
Comment on attachment 69284 [details, diff]
proposed-fix.patch

this patch is all mangled

either way, there's a version upstream which is not in portage which has this
fix
Comment 6 SpanKY gentoo-dev 2005-09-29 15:22:03 UTC
arc-5.21m now in portage
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-09-30 00:38:36 UTC
Archs, please test and mark stable :
Target KEYWORDS : "x86 ppc sparc alpha amd64 ppc64"
Comment 8 Fernando J. Pereda (RETIRED) gentoo-dev 2005-09-30 02:39:59 UTC
alpha keyword for free !!!!

Cheers,
Ferdy
Comment 9 Gustavo Zacarias (RETIRED) gentoo-dev 2005-09-30 10:11:03 UTC
sparc stable.
Comment 10 Markus Rothe (RETIRED) gentoo-dev 2005-09-30 11:18:30 UTC
stable on ppc64
Comment 11 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-09-30 11:21:36 UTC
Stable on ppc.
Comment 12 Simon Stelling (RETIRED) gentoo-dev 2005-09-30 13:09:46 UTC
amd64 stable
Comment 13 Paul Varner (RETIRED) gentoo-dev 2005-09-30 13:19:37 UTC
Stable on x86
Comment 14 Thierry Carrez (RETIRED) gentoo-dev 2005-09-30 13:54:08 UTC
Ready for GLSA vote
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2005-10-01 03:41:41 UTC
This is information disclosure, not symlink. I tend to vote no.
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-02 10:10:32 UTC
I tend to vote NO too. 
Comment 17 Thierry Carrez (RETIRED) gentoo-dev 2005-10-04 05:56:00 UTC
Let's close it, since nobody else wants to vote... Please reopen if you disagree.