Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 238575 (CVE-2008-4191) - app-accessibility/emacspeak <29.0 extract-table.pl Insecure temporary file creation (CVE-2008-4191)
Summary: app-accessibility/emacspeak <29.0 extract-table.pl Insecure temporary file cr...
Status: RESOLVED FIXED
Alias: CVE-2008-4191
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks: debian-tempfile
  Show dependency tree
 
Reported: 2008-09-24 15:42 UTC by Robert Buchholz (RETIRED)
Modified: 2009-01-11 17:49 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-09-24 15:42:38 UTC
CVE-2008-4191 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4191):
  extract-table.pl in Emacspeak 26 and 28 allows local users to
  overwrite arbitrary files via a symlink attack on the
  extract-table.csv temporary file.
Comment 1 William Hubbs gentoo-dev 2008-09-25 12:52:25 UTC
I have emailed upstream to ask about this issue; I am waiting for a response.
Comment 2 William Hubbs gentoo-dev 2008-09-26 00:10:22 UTC
All,

Upstream has notified me that this is fixed in their svn repository.  Should
I do an svn snapshot or wait until upstream does another release?

Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 17:05:45 UTC
29.0 is out, please bump.
Comment 4 William Hubbs gentoo-dev 2008-12-14 16:01:33 UTC
All,

emacspeak 29.0 is now in the tree.  Should I remove the older versions
immediately in this situation?
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-12-17 16:41:36 UTC
This also affected our stable 24. William, is 29.0 ok to go stable? You can simply remove the ~arch versions now and the arch ebuild once we pushed the latest version to stable.
Comment 6 William Hubbs gentoo-dev 2008-12-21 18:32:26 UTC
All,

I just did a quick test on 29.0, and let's go ahead and push it to stable.

Thanks,

William

Comment 7 William Hubbs gentoo-dev 2009-01-04 22:01:34 UTC
Adding arches.

ppc and x86, please stabilize this on your arch.

Thanks,

William

Comment 8 Robert Buchholz (RETIRED) gentoo-dev 2009-01-05 02:00:28 UTC
This call is for
=app-accessibility/emacspeak-29.0
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2009-01-09 16:30:18 UTC
ppc stable
Comment 10 Markus Meier gentoo-dev 2009-01-10 10:06:00 UTC
x86 stable, all arches done.
Comment 11 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-10 13:24:46 UTC
Ready for voting, I vote NO.
Comment 12 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2009-01-11 17:49:59 UTC
i vote no too. Feel free to reopen if you disagree.