Bug 208483 (CVE-2008-1694)

Summary: CVE-2008-1694 emacs insecure /tmp file usage
Product: [Other] Security Response Reporter: Steve Grubb <sgrubb>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: ovasik, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-02-17 15:09:50 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Patch fixing tmp file usage none

Description Steve Grubb 2006-09-28 20:03:24 UTC
Description of problem:
vcdiff script writes to a predictable tmp file. This could be used for attack by
malicious user.

Comment 1 Steve Grubb 2006-09-28 20:03:24 UTC
Created attachment 137341 [details]
Patch fixing tmp file usage

Comment 2 Lubomir Kundrak 2008-04-08 12:02:11 UTC
PATH=$PATH:/usr/ccs/bin:/usr/sccs:/usr/xpg4/bin # common SCCS hangouts

I don't like this either, it's unnecessary, but most likely has no security
consequences.

CVE Name was requested. Unless anyone objects, this will get public on Friday.
Chip, please communicate this upstream, and tell them not to commit fix until
friday.

Comment 3 Lubomir Kundrak 2008-04-08 16:04:54 UTC
CVE-2008-1694

Comment 9 Vincent Danen 2015-02-17 15:09:50 UTC
This issue was fixed prior to the GA releases of RHEL6 and 7.

Statement:

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.