Bug 1069034 - redis: insecure temporary file creation
Summary: redis: insecure temporary file creation
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1069035 1069036
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-02-24 02:17 UTC by Murray McAllister
Modified: 2019-09-29 13:13 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-09-07 08:01:34 UTC
Embargoed:


Attachments (Terms of Use)

Description Murray McAllister 2014-02-24 02:17:37 UTC
Matthew Hall reported that Redis, an advanced key-value store similar to memcached, insecurely created a temporary file. A local attacker could use this flaw to perform a symbolic link attack and possibly overwrite or delete an arbitrary file.

References:
https://github.com/antirez/redis/issues/1560

Comment 1 Murray McAllister 2014-02-24 02:19:26 UTC
The CVE will probably be posted to https://github.com/antirez/redis/issues/1560 once assigned

Comment 2 Murray McAllister 2014-02-24 02:20:12 UTC
Created redis tracking bugs for this issue:

Affects: fedora-all [bug 1069035]
Affects: epel-all [bug 1069036]

Comment 3 Murray McAllister 2014-02-24 02:48:14 UTC
(In reply to Murray McAllister from comment #1)
> The CVE will probably be posted to
> https://github.com/antirez/redis/issues/1560 once assigned

CVE request: http://seclists.org/oss-sec/2014/q1/423

Comment 4 Murray McAllister 2014-02-24 03:20:06 UTC
Seems like this may be expected behavior: http://seclists.org/oss-sec/2014/q1/425

Comment 5 Haïkel Guémar 2014-09-11 16:23:27 UTC
@Murray: could we close this ticket or should we fix that issue no matter what ?

Comment 6 Murray McAllister 2014-09-12 01:24:06 UTC
Hello,

The issue was rated Low so it is not urgent to fix. If you are able to fix it in just rawhide, then the ticket could be closed. However, if you cannot get a fix from upstream or are having problems there, the bug could be closed WONTFIX.

Comment 7 Haïkel Guémar 2014-09-13 13:15:03 UTC
Thanks, I'll do as you suggest.


Note You need to log in before you can comment on or make changes to this bug.