Bug 1192237 - procmail: unsafe handling of TZ environment variable
Summary: procmail: unsafe handling of TZ environment variable
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1203601
Blocks: 1192238
TreeView+ depends on / blocked
 
Reported: 2015-02-12 23:08 UTC by Kurt Seifried
Modified: 2019-09-29 13:28 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-03-18 20:43:07 UTC
Embargoed:


Attachments (Terms of Use)

Description Kurt Seifried 2015-02-12 23:08:23 UTC
It is reported that procmail has a similar flaw to sudo's CVE-2014-9680 in that procmail whitelists TZ values incorrectly.

External references:
http://openwall.com/lists/oss-security/2014/10/15/24
https://sources.debian.net/src/procmail/3.22-20%2Bdeb7u1/config.h/?hl=22#L13
http://seclists.org/oss-sec/2015/q1/533

Comment 2 Ján Rusnačko 2015-03-19 08:55:22 UTC
Created procmail tracking bugs for this issue:

Affects: fedora-all [bug 1203601]

Comment 4 Adam Mariš 2017-04-24 08:20:33 UTC
CVE-2014-9681 has been rejected. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.


Note You need to log in before you can comment on or make changes to this bug.