Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 265390 (CVE-2009-1253) - <media-sound/tunapie-2.1.16 Multiple vulnerabilities (CVE-2009-{1253,1254})
Summary: <media-sound/tunapie-2.1.16 Multiple vulnerabilities (CVE-2009-{1253,1254})
Status: RESOLVED FIXED
Alias: CVE-2009-1253
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://seclists.org/fulldisclosure/20...
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-04-07 23:43 UTC by Robert Buchholz (RETIRED)
Modified: 2009-04-30 10:00 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
tunapie-CVE-2009-1253+1254.patch (tunapie-CVE-2009-1253+1254.patch,3.04 KB, patch)
2009-04-07 23:45 UTC, Robert Buchholz (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-04-07 23:43:50 UTC
Several vulnerabilities have been discovered in Tunapie, a GUI frontend
to video and radio streams. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2009-1253

    Kees Cook discovered that insecure handling of temporary files may
    lead to local denial of service through symlink attacks.

CVE-2009-1254

    Mike Coleman discovered that insufficient escaping of stream
    URLs may lead to the execution of arbitrary commands if a user
    is tricked into opening a malformed stream URL.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-04-07 23:45:20 UTC
Created attachment 187655 [details, diff]
tunapie-CVE-2009-1253+1254.patch
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-04-07 23:45:54 UTC
Ubuntu bug: https://bugs.launchpad.net/bugs/314591
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-09 12:08:37 UTC
CVE-2009-1253 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1253):
  James Stone Tunapie 2.1 allows local users to overwrite arbitrary
  files via a symlink attack on an unspecified temporary file.

CVE-2009-1254 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1254):
  James Stone Tunapie 2.1 allows remote attackers to execute arbitrary
  commands via shell metacharacters in a stream URL.

Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2009-04-16 22:46:56 UTC
fixed in 2.1.16. Please bump.
Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2009-04-30 09:59:19 UTC
(In reply to comment #4)
> fixed in 2.1.16. Please bump.
> 

Thanks Robert

Bumped to 2.1.17 and removed old versions since there was no stable,
please just close this if you agree that there is no need for glsa.
Comment 6 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-04-30 10:00:36 UTC
thanks, closing with no GLSA since it's ~arch.