Bug 1088105 (CVE-2014-2893)

Summary: CVE-2014-2893 llvm: insecure temporary file handling in clang's scan-build utility
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: ajax, bos, davejohansen, dmalcolm, jkurik, jrusnack, jv+fedora, petersen, pfrields, scottt.tw, spacewar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-01-30 03:47:39 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1088107, 1088108    
Bug Blocks:    

Description Murray McAllister 2014-04-16 04:21:35 UTC
Jakub Wilk discovered that clang's scan-build utility insecurely handled temporary files. A local attacker could use this flaw to perform a symbolic link attack against users running the scan-build utility.

Original report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817

Comment 1 Murray McAllister 2014-04-16 04:23:12 UTC
This issue affects the llvm package in Fedora and EPEL. python-llvmpy and mingw-llvm are not affected.

Comment 2 Murray McAllister 2014-04-16 04:24:19 UTC
Created llvm tracking bugs for this issue:

Affects: fedora-all [bug 1088107]
Affects: epel-6 [bug 1088108]

Comment 3 Murray McAllister 2014-04-16 04:28:04 UTC
CVE request: http://www.openwall.com/lists/oss-security/2014/04/16/2

Comment 4 Murray McAllister 2014-04-22 05:22:34 UTC
MITRE assigned CVE-2014-2893 to this issue:

http://seclists.org/oss-sec/2014/q2/144

Comment 6 Fedora Update System 2014-12-21 17:43:22 UTC
llvm-3.4.2-3.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2014-12-21 17:43:47 UTC
llvm-3.4.2-3.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.