Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 189440 - app-text/po4a < 0.32-r1 possible race condition (CVE-2007-4462)
Summary: app-text/po4a < 0.32-r1 possible race condition (CVE-2007-4462)
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
Whiteboard: B1? [glsa]
Depends on:
Reported: 2007-08-19 09:42 UTC by Christian Hartmann (RETIRED)
Modified: 2008-01-10 08:59 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---

output of perl-info (perl-info,3.36 KB, text/plain)
2007-08-23 20:42 UTC, Christoph Mende (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Christian Hartmann (RETIRED) gentoo-dev 2007-08-19 09:42:51 UTC
* Major changes in release 0.32 (2007-08-15)

** Security fix
  Fix a possible race condition on a file created in /tmp.

app-text/po4a-0.32 is in portage now.

Security please advice. Thanks in advance!
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2007-08-19 18:56:58 UTC
Thanks ian. arches, please test and mark stable if this suits your current tree.
Comment 2 Jeroen Roovers gentoo-dev 2007-08-19 19:59:55 UTC
Stable for HPPA.

Seems like a couple of arches are missing in the CC field.
Comment 3 Ferris McCormick (RETIRED) gentoo-dev 2007-08-19 20:37:04 UTC
Sparc stable --- all 134 tests pass and it creates its translations successfully, installs as expected.
Comment 4 Markus Ullmann (RETIRED) gentoo-dev 2007-08-21 12:18:42 UTC
On x86 I get this:

Safe to ignore?

#   Failed test 'normalisation test returns what is expected'
#   at t/20-sgml.t line 65.
# Failed (retval=256) on:
# diff -u  -I '^# SOME' -I '^# Test' -I '^"POT-Creation-Date: ' -I '^"Content-Transfer-Encoding:' data-20/test2.pot tmp/po4a-normalize.po&& diff -u  -I '^# SOME' -I '^# Test' -I '^"POT-Creation-Date: ' -I '^"Content-Transfer-Encoding:' data-20/test2-normalized.sgml tmp/po4a-normalize.output
# Was created with:
# perl -I../lib cd tmp && perl ../../po4a-normalize -f sgml ../data-20/test2.sgml
# Looks like you failed 1 test of 4.
        Test returned status 1 (wstat 256, 0x100)
        Failed 1/4 tests, 75.00% okay
Failed Test Stat Wstat Total Fail  List of Failed
t/20-sgml.t    1   256     4    1  4
Failed 1/12 test scripts. 1/134 subtests failed.
Files=12, Tests=134, 14 wallclock secs (11.17 cusr +  2.26 csys = 13.43 CPU)
Failed 1/12 test programs. 1/134 subtests failed.

!!! ERROR: app-text/po4a-0.32 failed.
Call stack:, line 1638:   Called dyn_test, line 1047:   Called qa_call 'src_test', line 44:   Called src_test, line 1328:   Called perl-module_src_test
  perl-module.eclass, line 155:   Called die

!!! test failed
!!! If you need support, post the topmost build error, and the call stack if relevant.
!!! A complete build log is located at '/var/log/portage/app-text:po4a-0.32:20070821-115122.log'.

+w+ emerge returned 1
+m+ all done
(tinderbox) localhost / #       
Comment 5 Christoph Mende (RETIRED) gentoo-dev 2007-08-22 23:05:45 UTC
same test failures on amd64
Comment 6 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-23 09:51:22 UTC
uncalling arches until this gets fixed, and cc'ing herd. Perl please advise.
Comment 7 Christian Hartmann (RETIRED) gentoo-dev 2007-08-23 19:40:02 UTC
I'm unable to reproduce this error on any of my boxes.

Markus, Christoph:
Could you please provide the output of `perl-info` (you'd probably need to emerge it first)?
Comment 8 Christoph Mende (RETIRED) gentoo-dev 2007-08-23 20:42:52 UTC
Created attachment 129007 [details]
output of perl-info
Comment 9 Christian Hartmann (RETIRED) gentoo-dev 2007-08-25 11:37:42 UTC
I'm now able to reproduce this bug and I've spend some time looking into it but cannot explain what actually is causing this odd behaviour.

About to contact upstream.
Comment 10 Christian Hartmann (RETIRED) gentoo-dev 2007-08-25 17:56:07 UTC
Could you please confirm that the tests now work fine in 0.32-r1?
Comment 11 Christoph Mende (RETIRED) gentoo-dev 2007-08-25 18:04:04 UTC
test suite passes with -r1, amd64 stable
Comment 12 Christian Hartmann (RETIRED) gentoo-dev 2007-08-26 15:09:26 UTC
Arches please stable app-text/po4a-0.32-r1.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-27 09:33:27 UTC
amd64 is already stable.
Comment 14 Ferris McCormick (RETIRED) gentoo-dev 2007-08-27 11:46:28 UTC
Sparc stable (tests run successfully, and it can build itself).
Comment 15 Jeroen Roovers gentoo-dev 2007-08-27 20:57:26 UTC
Stable for HPPA.
Comment 16 Markus Ullmann (RETIRED) gentoo-dev 2007-08-27 22:39:25 UTC
Stable on x86
Comment 17 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 15:58:51 UTC
err, seems that some arches don't have a stable fixed version while they have a vulnerable stable version. That's not too annoying since they aren't security supported, but cc'ing so they can stable it eventually.
Comment 18 Raúl Porcel (RETIRED) gentoo-dev 2007-09-13 17:20:50 UTC
I stabilized this the other day on ia64
Comment 19 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-09-14 21:24:13 UTC
it's GLSA 200709-04. Thanks everybody.

arm, s390, feel free to stabilize whenever you want