Bug 169585

Summary: CAN-2005-3011 texindex insecure temporary file usage
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: texinfoAssignee: Tim Waugh <twaugh>
Status: CLOSED ERRATA QA Contact: Ben Levenson <benl>
Severity: low Docs Contact:
Priority: medium    
Version: 4Keywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,source=cve,public=20000209,reported=20050921
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-10-17 10:57:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-09-29 21:01:40 UTC
+++ This bug was initially created as a clone of Bug #169583 +++

The texindex command uses predictable temporary filenames.  This could allow a
rogue local user to create a symlink which would cause texindex to overwrite
various files the user running texindex has write access to.

There is more informatin in the Debian bug:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328365

No patch exists yet.


This issue seems to be mitigated by the fact that texindex will only use a
temporary file when the file being processed is over 50,000 lines.

Comment 1 Josh Bressers 2005-09-29 21:03:00 UTC
This issue should also affect FC3

Comment 3 Fedora Update System 2005-10-14 15:58:03 UTC
From User-Agent: XML-RPC

texinfo-4.8-4.1 has been pushed for FC4, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.