Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 714102 (CVE-2020-10870) - <x11-misc/zim-0.73.0: Predictable tmpfile allows denial of service (CVE-2020-10870)
Summary: <x11-misc/zim-0.73.0: Predictable tmpfile allows denial of service (CVE-2020-...
Status: RESOLVED FIXED
Alias: CVE-2020-10870
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/mssalvatore/zim-de...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-03-23 20:01 UTC by Sam James
Modified: 2020-07-18 00:19 UTC (History)
1 user (show)

See Also:
Package list:
=x11-misc/zim-0.73.1
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-23 20:01:48 UTC
Description:
"Zim creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service."

Patch: https://github.com/mssalvatore/zim-desktop-wiki/commit/745bb80f081ee99569df57be30ed17e666510040
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-26 18:30:09 UTC
0.73 has not yet been released (so not in tree/ready for stabilisation).
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2020-03-27 13:04:12 UTC
(In reply to Sam James (sam_c) (security padawan) from comment #1)
> 0.73 has not yet been released (so not in tree/ready for stabilisation).

Are you guys still doing that?
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-27 21:38:59 UTC
(In reply to Jeroen Roovers from comment #2)
> (In reply to Sam James (sam_c) (security padawan) from comment #1)
> > 0.73 has not yet been released (so not in tree/ready for stabilisation).
> 
> Are you guys still doing that?

Yeah, I didn't realise at first, the reason is because it's easier to make the GLSAs if we know the exact first fixed version in tree. If the first fixed release in tree isn't the first fixed release by upstream, it can be confusing.

https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Guide#Bug_summary_rules
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-07 00:18:35 UTC
@maintainer(s), please build to 0.73.0.
Comment 5 Larry the Git Cow gentoo-dev 2020-06-08 09:08:01 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e6c3702878aea7ea47f50e6adfe1d6a8696a4cec

commit e6c3702878aea7ea47f50e6adfe1d6a8696a4cec
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-06-08 09:07:33 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-06-08 09:07:57 +0000

    x11-misc/zim: Version 0.73.0
    
    Package-Manager: Portage-2.3.100, Repoman-2.3.22
    Bug: https://bugs.gentoo.org/714102
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 x11-misc/zim/Manifest          |  1 +
 x11-misc/zim/zim-0.73.0.ebuild | 79 ++++++++++++++++++++++++++++++++++++++++++
 2 files changed, 80 insertions(+)
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-22 20:45:54 UTC
0.73.1 fixes a regression, so I guess that is the stable target: https://github.com/zim-desktop-wiki/zim-desktop-wiki/compare/0.73.0...0.73.1

No open bugs, so if no objections, I'll CC arches.
Comment 7 Agostino Sarubbo gentoo-dev 2020-07-05 13:36:32 UTC
amd64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2020-07-05 13:45:18 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 9 Larry the Git Cow gentoo-dev 2020-07-05 14:42:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2ce030ef9aedc304ab3f27a55b0d9b5e008847a0

commit 2ce030ef9aedc304ab3f27a55b0d9b5e008847a0
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-07-05 14:42:10 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-07-05 14:42:38 +0000

    x11-misc/zim: Old
    
    Package-Manager: Portage-2.3.103, Repoman-2.3.23
    Bug: https://bugs.gentoo.org/show_bug.cgi?id=714102
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 x11-misc/zim/Manifest             |  2 -
 x11-misc/zim/zim-0.72.1-r2.ebuild | 79 ---------------------------------------
 x11-misc/zim/zim-0.73.0.ebuild    | 79 ---------------------------------------
 3 files changed, 160 deletions(-)
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-18 00:19:41 UTC
GLSA vote: no.

Tree is clean, closing.