Bug 155749
Summary: | CVE-2005-1111 Race condition in cpio | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 4 | Reporter: | Josh Bressers <bressers> | ||||||
Component: | cpio | Assignee: | Peter Vrabec <pvrabec> | ||||||
Status: | CLOSED ERRATA | QA Contact: | Brock Organ <borgan> | ||||||
Severity: | medium | Docs Contact: | |||||||
Priority: | medium | ||||||||
Version: | 4.0 | CC: | tao | ||||||
Target Milestone: | --- | Keywords: | Security | ||||||
Target Release: | --- | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
Whiteboard: | impact=moderate,public=20050413,source=bugtraq,reported=20050413 | ||||||||
Fixed In Version: | RHSA-2005:378 | Doc Type: | Bug Fix | ||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2006-04-30 02:51:31 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Attachments: |
|
Description
Josh Bressers
2005-04-22 18:45:45 UTC
This issue should also affect RHEL2.1 and RHEL3. Created attachment 113839 [details]
Proposed patch from Steve Grubb
Created attachment 116230 [details]
I suggest to use this patch.
Steve's patch doesn't solve race condition on directories. My fix use mode 0700
for dir creation, which close some more holes.
We have not released an update for this issue on RHEL2.1 yet. RHEL3 and RHEL4 were fixed in RHSA-2005:378 The RHEL 2.1 bug in being tracked in bug #169760 |