Bug 136300 - CAN-2004-0977 temporary file vulnerabilities in make_oidjoins_check script
Summary: CAN-2004-0977 temporary file vulnerabilities in make_oidjoins_check script
Alias: None
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: rh-postgresql (Show other bugs)
(Show other bugs)
Version: 3.0
Hardware: All Linux
Target Milestone: ---
Assignee: Tom Lane
QA Contact:
Whiteboard: public=20040930,impact=low
Keywords: Security
Depends On:
TreeView+ depends on / blocked
Reported: 2004-10-19 09:42 UTC by Mark J. Cox
Modified: 2013-07-03 03:02 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2004-12-20 17:54:14 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
tempfile patch from vendor-sec (1.42 KB, patch)
2004-10-19 09:43 UTC, Mark J. Cox
no flags Details | Diff

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2004:489 normal SHIPPED_LIVE Low: rh-postgresql security update 2004-12-20 05:00:00 UTC

Description Mark J. Cox 2004-10-19 09:42:08 UTC
On September 10th 2004, Trustix shared some temporary file
vulnerabilities with vendor-sec.  After some refinement these were
made public on Sep30.  These are minor issues (impact: LOW) and
therefore should be fixed in future updates, but don't deserve their
own security advisory.

Temporary file vulnerability in make_oidjoins_check script.  Patch
attached.  Part of rh-postgresql-contrib therefore affects RHEL3

This issue does not affect the RHEL2.1 postgresql packages which did
not contain this script.

Comment 1 Mark J. Cox 2004-10-19 09:43:25 UTC
Created attachment 105429 [details]
tempfile patch from vendor-sec

Comment 2 Tom Lane 2004-10-19 14:16:57 UTC
What we have here is an unportable solution to a non-problem. 
make_oidjoins_check is never run by users, and in any case the worst
someone could do is screw up the regression test script it creates,
which would certainly be noticed before the script got used in

I might be more excited about applying this if the proposed mktemp
call hadn't failed outright on the system that I would actually be
likely to be running make_oidjoins_check on for future PG releases;
but as is, the patch is unacceptable upstream, and I don't think it's
worth the trouble to try to develop a portable invocation of mktemp
for this.

A more likely patch would be to remove the script from the RPM
entirely ... it seems like a waste of space to have it there.

Comment 4 Tom Lane 2004-10-19 15:37:00 UTC
It certainly wouldn't ever be run as root --- it's basically a tool
that is used about once per release cycle to update the oidjoins
regression test script to match the system catalogs' foreign-key

Also the attacker couldn't control what was going to be written, so
the vulnerability seems essentially nil to me.  Taking the script out
of the distro is definitely the most reasonable response.

Comment 5 Tom Lane 2004-10-26 01:03:53 UTC
This is repaired in rh-postgresql-7.3.8-1.

Comment 6 John Flanagan 2004-12-20 17:54:14 UTC
An errata has been issued which should help the problem 
described in this bug report. This report is therefore being 
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, 
please follow the link below. You may reopen this bug report 
if the solution does not work for you.


Note You need to log in before you can comment on or make changes to this bug.