Bug 155751
Summary: | CAN-2005-1111 Race condition in cpio | ||||||
---|---|---|---|---|---|---|---|
Product: | [Retired] Fedora Legacy | Reporter: | Josh Bressers <bressers> | ||||
Component: | cpio | Assignee: | Fedora Legacy Bugs <bugs> | ||||
Status: | CLOSED CANTFIX | QA Contact: | Brock Organ <borgan> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | fc3 | CC: | mattdm, michal | ||||
Target Milestone: | --- | Keywords: | Reopened, Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | impact=moderate,public=20050413,source=bugtraq,reported=20050413 | ||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2007-04-10 19:16:39 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Attachments: |
|
Description
Josh Bressers
2005-04-22 18:51:29 UTC
Created attachment 113628 [details]
patch fix cpio-2.6 race condition
I replaced some chown, chmod with fchmod and fchown. And close file descriptor
later.
This bug is CLOSED RAWHIDE, and hopefuly fixed in cpio-2.6-7 from FC4 although there is no explicit note to the effect in a changelog there, but I do not see a security update for FC3 which would cover that bug and also CAN-2005-1229 (bug #156314) and this leaves those installations vulnerable. Reopening as per comment #2. also, confirming that this is fixed in FC4 and on. Fedora Core 3 is now completely unmaintained. These bugs can't be fixed in that version. If the issue still persists in current Fedora Core, please reopen. Thank you, and sorry about this. |