[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE Request -- coreutils -- unsafe temporary
From:       Josh Bressers <bressers () redhat ! com>
Date:       2009-12-08 20:35:19
Message-ID: 1989820797.872961260304519281.JavaMail.root () zmail01 ! collab ! prod ! int ! phx2 ! redhat ! com
[Download RAW message or body]

Please use CVE-2009-4135 for this.

Thanks.

-- 
    JB


----- "Jan Lieskovsky" <jlieskov@redhat.com> wrote:

> Hi Steve, vendors,
> 
>    Jim Meyering reported a flaw in coreutils in the way, its
> "distcheck" Makefile rule used to set up a temporary directory
> location to be used later for performing its own tasks.
> This might allow local attacker to conduct symlink attacks or
> potentially execute arbitrary code under certain circumstances.
> 
> Upstream patch:
> --------------
> http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5
> 
> Affected versions:
> ------------------
> coreutils-5.2.1 through to coreutils-8.1
> 
> References:
> -----------
> https://bugzilla.redhat.com/show_bug.cgi?id=545439
> http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5
> http://thread.gmane.org/gmane.comp.gnu.coreutils.bugs/19199
> 
> Could you allocate a CVE identifier for this issue?
> 
> Thanks && Regards, Jan.
> --
> Jan iankko Lieskovsky / Red Hat Security Response Team
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic