Bug 470795 (CVE-2008-4993)

Summary: CVE-2008-4993 xen: insecure temporary file use in qemu-dm.debug
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: bburns, berrange, clalance, ovirt-maint, xen-maint
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4993
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-11-24 22:01:48 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 470808, 470809    
Bug Blocks:    

Description Tomas Hoger 2008-11-10 11:04:17 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4993 to the following vulnerability:

qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary
files via a symlink attack on the /tmp/args temporary file.

References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496367
https://bugs.gentoo.org/show_bug.cgi?id=235805
http://dev.gentoo.org/~rbu/security/debiantemp/xen-utils-3.2-1

Comment 1 Tomas Hoger 2008-11-10 11:06:09 UTC
This debug script is shipped in xen packages in Red Hat Enterprise Linux 5 and Fedora 8.  As of Fedora 9, most of the tools are moved to separate subpackage - xen-runtime - which does not ship qemu-dm.debug script.

Comment 2 Tomas Hoger 2008-11-10 11:08:37 UTC
This seems to be quite dummy debug script, that is probably used by xen developers.  Can it possibly have any use on production deployments?

Comment 3 Daniel Berrangé 2008-11-10 11:17:19 UTC
I killed it off in Fedora 9 because it is a waste of time shipping it - anyone can trivially create something similar & more suitable to their needs. So I vote for killing it off everywhere else too.

Comment 7 Chris Lalancette 2009-11-24 22:01:48 UTC
I do believe the errata was shipped for this a long time ago in all relevant packages, so I'm closing this tracking bug.

Chris Lalancette