Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 449792 (CVE-2012-6076) - <media-gfx/inkscape-0.48.4: Reads .eps files from /tmp instead of current working directory (CVE-2012-6076)
Summary: <media-gfx/inkscape-0.48.4: Reads .eps files from /tmp instead of current wor...
Status: RESOLVED FIXED
Alias: CVE-2012-6076
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-02 17:17 UTC by Agostino Sarubbo
Modified: 2013-04-01 15:48 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-01-02 17:17:25 UTC
From $URL :

An untrusted directory search path vulnerability was found in the way Inkscape, a vector graphics 
editor, using the W3C standard Scalable Vector Graphics (SVG) file format, loaded EPS (Encapsulated 
PostScript) files. A local attacker could use this flaw to execute arbitrary PostScript code with 
the privileges of the user running the inkscape executable.

References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654341
[2] https://bugs.launchpad.net/inkscape/+bug/911146
[3] http://www.openwall.com/lists/oss-security/2012/12/29/5
[4] http://www.openwall.com/lists/oss-security/2012/12/30/2
[5] https://bugzilla.novell.com/show_bug.cgi?id=796306

Relevant patch:
[6] 
http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=47;filename=0005-Add-patch-to-fix-upstream-vulnerability-LP-911146.patch;att=5;bug=654341
[7] https://bugs.launchpad.net/inkscape/+bug/911146/comments/2 (but see also subsequent comments 
wrt to the patch regression)
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-03 14:18:58 UTC
GLSA vote: no.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-03-21 18:33:11 UTC
CVE-2012-6076 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-6076):
  Inkscape before 0.48.4 reads .eps files from /tmp instead of the current
  directory, which might cause Inkspace to process unintended files, allow
  local users to obtain sensitive information, and possibly have other
  unspecified impacts.
Comment 3 Tobias Heinlein (RETIRED) gentoo-dev 2013-04-01 15:48:34 UTC
NO too, closing.