Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 245760 (CVE-2008-4938) - dev-util/aegis<=4.24 symlink attack (CVE-2008-4938)
Summary: dev-util/aegis<=4.24 symlink attack (CVE-2008-4938)
Status: RESOLVED FIXED
Alias: CVE-2008-4938
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://sourceforge.net/tracker/index....
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks: debian-tempfile
  Show dependency tree
 
Reported: 2008-11-05 22:01 UTC by Stefan Behte (RETIRED)
Modified: 2010-08-14 14:21 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-11-05 22:01:08 UTC
CVE-2008-4938 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4938):
  aegis 4.24 and aegis-web 4.24 allow local users to overwrite
  arbitrary files via a symlink attack on (a) /tmp/#####, (b)
  /tmp/#####.intro, (c) /tmp/aegis.#####.ae, (d) /tmp/aegis.#####, (e)
  /tmp/aegis.#####.1, (f) /tmp/aegis.#####.2, (g) /tmp/aegis.#####.log,
  and (h) /tmp/aegis.#####.out temporary files, related to the (1)
  bng_dvlpd.sh, (2) bng_rvwd.sh, (3) awt_dvlp.sh, (4) awt_intgrtn.sh,
  and (5) aegis.cgi scripts.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-05 22:04:33 UTC
From #235770:
DEBIAN: http://bugs.debian.org/496402
DEBIAN: http://bugs.debian.org/496400
FILES: bng_dvlpd.sh, bng_rvwd.sh, awt_dvlp.sh, awt_intgrtn.sh, aegis.cgi
CODE: http://dev.gentoo.org/~rbu/security/debiantemp/aegis
CODE: http://dev.gentoo.org/~rbu/security/debiantemp/aegis-web

Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 16:29:29 UTC
No maintainer...shall we remove or hardmask it?!
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-07-13 00:20:23 UTC
awt_dvlp.sh, awt_intgrtn.sh is addressed in 4.24.1 via 
http://sourceforge.net/tracker/index.php?func=detail&aid=2079025&group_id=224&atid=100224

aegis.cgi is removed in 4.24.1, a patch would have been here:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496400#24

upstream bug for the remaining files:
https://sourceforge.net/tracker/?func=detail&aid=2820524&group_id=224&atid=100224
Comment 4 Diego Elio Pettenò (RETIRED) gentoo-dev 2010-01-05 23:26:48 UTC
Since I got two bugs open for this package already, should we go looking for somebody to fix this?
Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2010-02-17 16:18:28 UTC
Masked for removal
Comment 6 Samuli Suominen (RETIRED) gentoo-dev 2010-03-05 17:09:10 UTC
(In reply to comment #5)
> Masked for removal
> 

Removed from tree (in light of on-going dev-vcs category moving.)
Comment 7 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-04-02 16:21:47 UTC
GLSA: no
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2010-08-14 14:21:22 UTC
NO too, closing.