Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 22483 - sys-apps/gzip
Summary: sys-apps/gzip
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-06-09 06:04 UTC by Daniel Ahlberg (RETIRED)
Modified: 2003-06-14 09:48 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-06-09 06:04:26 UTC
[SECURITY] [DSA-308-1] New gzip packages fix insecure temporary file creation 
 
From:  
Matt Zimmerman <mdz@debian.org> 
 
 
To:  
bugtraq@securityfocus.com 
 
 
Date:  
Saturday 03.51.42 
 
 
 
Message was signed with unknown key 0x43E25D1E. 
The validity of the signature cannot be verified. 
 
 
-------------------------------------------------------------------------- 
Debian Security Advisory DSA 308-1                     security@debian.org 
http://www.debian.org/security/                             Matt Zimmerman 
June 6th, 2003                          http://www.debian.org/security/faq 
-------------------------------------------------------------------------- 
 
Package        : gzip 
Vulnerability  : insecure temporary files 
Problem-Type   : local 
Debian-specific: no 
CVE Ids        : CVE-1999-1332, CAN-2003-0367 
 
Paul Szabo discovered that znew, a script included in the gzip 
package, creates its temporary files without taking precautions to 
avoid a symlink attack (CAN-2003-0367). 
 
The gzexe script has a similar vulnerability which was patched in an 
earlier release but inadvertently reverted. 
 
For the stable distribution (woody) both problems have been fixed in 
version 1.3.2-3woody1. 
 
For the old stable distribution (potato) CAN-2003-0367 has been fixed 
in version 1.2.4-33.2.  This version is not vulnerable to 
CVE-1999-1332 due to an earlier patch. 
 
For the unstable distribution (sid) this problem will be fixed soon. 
 
We recommend that you update your gzip package. 
 
Upgrade Instructions 
-------------------- 
 
wget url 
        will fetch the file for you 
dpkg -i file.deb 
        will install the referenced file. 
 
If you are using the apt-get package manager, use the line for 
sources.list as given below: 
 
apt-get update 
        will update the internal database 
apt-get upgrade 
        will install corrected packages 
 
You may use an automated update by adding the resources from the 
footer to the proper configuration. 
 
Debian GNU/Linux 3.0 alias woody 
-------------------------------- 
 
  Source archives: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1.dsc 
      Size/MD5 checksum:      577 affc0d3b073378cd2dc13c2a6772810a 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1.diff.gz 
      Size/MD5 checksum:     5554 abd3dee3183d8c20f58c792206cec6e5 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2.orig.tar.gz 
      Size/MD5 checksum:   311011 57bff96b6b4bcbb060566bdbed29485d 
 
  Alpha architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_alpha.deb 
      Size/MD5 checksum:    76240 8b1022a3708b29162831ae85307cb4de 
 
  ARM architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_arm.deb 
      Size/MD5 checksum:    68538 8f640e909866da6602c2854375fa3b70 
 
  Intel IA-32 architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_i386.deb 
      Size/MD5 checksum:    61868 a224c831e1a801e980801b63fde5a031 
 
  Intel IA-64 architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_ia64.deb 
      Size/MD5 checksum:    86622 67e08c2b9b1011544b8303376f920df7 
 
  HP Precision architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_hppa.deb 
      Size/MD5 checksum:    72366 334d7a9b874026c95ea4a3b37b693691 
 
  Motorola 680x0 architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_m68k.deb 
      Size/MD5 checksum:    61134 0e8cc087cfb00ec478c48c6f0b177ea1 
 
  Big endian MIPS architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_mips.deb 
      Size/MD5 checksum:    71524 acc8077c42714b77a73e55ae77a6493f 
 
  Little endian MIPS architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_mipsel.deb 
      Size/MD5 checksum:    71388 c81151864b2453826712ac969e73535c 
 
  PowerPC architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_powerpc.deb 
      Size/MD5 checksum:    69062 91de386eef5133dbd777934a3ff6668f 
 
  IBM S/390 architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_s390.deb 
      Size/MD5 checksum:    66508 391497f880223b95fbf2b6b3d72160eb 
 
  Sun Sparc architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody1_sparc.deb 
      Size/MD5 checksum:    70058 3c9c0854327fec243b228108ec29f4b8 
 
Debian GNU/Linux 2.2 alias potato 
--------------------------------- 
 
  Source archives: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2.dsc 
      Size/MD5 checksum:      542 0c5d9c072d3b99c09cf139799b1c1031 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2.diff.gz 
      Size/MD5 checksum:    10142 0cec25832d0eaff865a27489f0757d8b 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4.orig.tar.gz 
      Size/MD5 checksum:   220976 b94b3e07797e0cbf3622bb2fe5682f0b 
 
  Alpha architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2_alpha.deb 
      Size/MD5 checksum:    78936 a17b1e7130835c9f08bec9b0ff715bb1 
 
  ARM architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2_arm.deb 
      Size/MD5 checksum:    68906 9f0730655e6b5011a0b69800cc032e89 
 
  Intel IA-32 architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2_i386.deb 
      Size/MD5 checksum:    62820 77377a288598140ab73d58952c8f2ea4 
 
  Motorola 680x0 architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2_m68k.deb 
      Size/MD5 checksum:    62110 27c2275eb1b2331b6b2444fec1e0cc7b 
 
  PowerPC architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2_powerpc.deb 
      Size/MD5 checksum:    69882 5b91a3a96fb4bc6efb0d98402f55c4a6 
 
  Sun Sparc architecture: 
 
    http://security.debian.org/pool/updates/main/g/gzip/gzip_1.2.4-33.2_sparc.deb 
      Size/MD5 checksum:    71404 4e404ee1024af95725b99abe05bbecf5 
 
 
These files will probably be moved into the stable distribution on its 
next revision. 
 
--------------------------------------------------------------------------------- 
For apt-get: deb http://security.debian.org/ stable/updates main 
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main 
Mailing list: debian-security-announce@lists.debian.org 
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> 
 
 
End of signed message
Comment 1 solar (RETIRED) gentoo-dev 2003-06-09 15:12:33 UTC
# emerge -pv gzip
[ebuild   R  ] sys-apps/gzip-1.3.3-r1  +nls -build

# strace -ff -eopen znew
open("/tmp/zfoo.21403.1", O_WRONLY|O_CREAT|O_EXCL|O_LARGEFILE, 0666) = 3
open("/tmp/zfoo.21403.2", O_WRONLY|O_CREAT|O_EXCL|O_LARGEFILE, 0666) = 3

At a quick glance we do seem vuln to this problem. I didnt check gzexe and am unaware if its has the same problems outlined in debs announcement. Anyway patches should be made and a GLSA should go out ASAP.
Comment 2 Daniel Ahlberg (RETIRED) gentoo-dev 2003-06-14 09:48:58 UTC
glsa sent