Bug 970172 (CVE-2013-2142)
Summary: | CVE-2013-2142 libimobiledevice: Insecure temporary file use when both $XDG_CONFIG_HOME and $HOME are unset | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | bnocera, cfergeau, jlieskov, jrusnack, pbrobinson |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2015-03-20 18:45:18 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 951167, 970175 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2013-06-03 15:21:58 UTC
This issue did NOT affect the version of the libimobiledevice, as shipped with Red Hat Enterprise Linux 6. -- This issue affects the versions of the libimobiledevice, as shipped with Fedora release of 17 and 18. Please schedule an update (once there is final upstream patch available). Created libimobiledevice tracking bugs for this issue Affects: fedora-all [bug 970175] Statement: Not vulnerable. This issue did not affect the version of libimobiledevice as shipped with Red Hat Enterprise Linux 6 as it did not include the upstream commit 825da48d2e9c20086c4e34869da0b28376676b4c that introduced this issue. The CVE identifier of CVE-2013-2142 has been assigned to this issue: http://www.openwall.com/lists/oss-security/2013/06/04/11 Does this also affect unreleased versions? Relevant upstream patch: http://cgit.sukimashita.com/libimobiledevice.git/commit/?id=a2ddca0916ef776dbd0c6304ea36b4ca7a35302c (In reply to Bastien Nocera from comment #6) > Does this also affect unreleased versions? Looks it got fixed in 1.2.0 upstream version already. I don't have iPod phone to try if the fix works, but patch in previous comment seems to be applicable to recent Fedora versions. libplist-1.11-2.fc20, libusbmuxd-1.0.9-2.fc20, libimobiledevice-1.1.6-2.fc20, usbmuxd-1.0.9-0.4.c24463e.fc20, ifuse-1.1.3-3.fc20, libgpod-0.8.3-2.fc20, upower-0.9.23-3.fc20, gvfs-1.18.3-3.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. Fixed in all current Fedora releases |