Bug 158995 (CVE-2005-1751)
| Summary: | CVE-2005-1751 shtool: insecure temporary file creation | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Josh Bressers <bressers> | ||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
| Status: | CLOSED WONTFIX | QA Contact: | |||||
| Severity: | low | Docs Contact: | |||||
| Priority: | low | ||||||
| Version: | unspecified | CC: | osoukup | ||||
| Target Milestone: | --- | Keywords: | Security | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2011-06-29 14:38:48 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
|
Description
Josh Bressers
2005-05-27 15:22:07 UTC
This issue should also affect RHEL2.1 and RHEL3 shtool is only used in the build process. So a user can only be compromised, when he rebuilds nmap.. Correct, please just keep this fix on the shelf for the next nmap update. Red Hat Enterprise Linux 2.1 and 3 reached end of life already. Red Hat Enterprise Linux 4 is in the Production 3 phase of its life cycle: https://access.redhat.com/support/policy/updates/errata/ There is no plan to address this flaw in Red Hat Enterprise Linux 4, as it does not affect binary nmap packages, and is only a problem during the package rebuilds. Created attachment 510494 [details]
Upstream fix
Upstream change extracted from 2.0.1 -> 2.0.2 diff. Noted for posterity.
I have double-checked shtool version bundled with nmap sources in Red Hat Enterprise Linux 3 and 4. That version did not contain relevant code for creating temporary files, and hence were not affected by this problem. This issue was addressed in the shtool version embedded with PHP versions in Red Hat Enterprise Linux 3 and 4: https://www.redhat.com/security/data/cve/CVE-2005-1751.html Upstream PHP bug indicates affected code was not used during PHP build: https://bugs.php.net/bug.php?id=33150 The shtool version containing this bug is part of openldap sources (RHEL-4 and compat in RHEL-5) and rrdtool sources (RHEL-6), but the affected code is not used. Other components embedding shtool shipped in Red Hat Enterprise Linux contain patched upstream shtool version (php, openldap, pth, nmap in RHEL-5 and RHEL-6, and lzo, lzop, uuid in RHEL-6). |