This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours

Bug 1048678 (CVE-2014-0027)

Summary: CVE-2014-0027 flite: insecure temporary file use
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fweimer, jrusnack, pfrields, rmatos, security-response-team, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20140110,reported=20140102,source=redhat,cvss2=3.6/AV:L/AC:L/Au:N/C:P/I:P/A:N,rhel-7/flite=notaffected,fedora-all/flite=affected,epel-all/flite=affected,cwe=CWE-377
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-01-09 22:08:48 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 1050995, 1050997, 1050998    
Bug Blocks: 1023438, 1048682    
Attachments:
Description Flags
proposed patch none

Description Murray McAllister 2014-01-06 00:45:19 EST
It was found that flite, a speech synthesis engine (text-to-speech), insecurely used a temporary file. A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running flite, or possibly obtain sensitive information as the temporary file may contain text-to-speech output (screen contents).

Acknowledgements:

This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
Comment 6 Rui Matos 2014-01-06 09:24:51 EST
Created attachment 846118 [details]
proposed patch
Comment 11 Murray McAllister 2014-01-09 08:57:27 EST
Created flite tracking bugs for this issue:

Affects: fedora-all [bug 1050997]
Affects: epel-all [bug 1050998]
Comment 12 Huzaifa S. Sidhpurwala 2014-01-09 22:08:48 EST
This issue affects the version of flite package as shipped with Fedora 19 and Fedora 20.

This issue affects the version of flite package as shipped with epel-5 and epel-6.
Comment 13 Fedora Update System 2014-02-04 22:38:35 EST
flite-1.3-20.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 14 Fedora Update System 2014-02-04 22:43:23 EST
flite-1.3-21.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.