Bug 154051 - CAN-2005-0990 unsecure temp file usage
Summary: CAN-2005-0990 unsecure temp file usage
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: sharutils
Version: 3
Hardware: All
OS: Linux
medium
low
Target Milestone: ---
Assignee: Than Ngo
QA Contact:
URL:
Whiteboard: impact=low,public=20050331,source=cve...
Depends On:
Blocks: 154991
TreeView+ depends on / blocked
 
Reported: 2005-04-06 20:50 UTC by Josh Bressers
Modified: 2007-11-30 22:11 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-08-20 07:32:39 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2005-04-06 20:50:37 UTC
+++ This bug was initially created as a clone of Bug #154049 +++

The way sharutils handles temporary files is insecure (as reported by the Debian
BTS):
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=302412

The Debian bug contains a patch for this issue.

Comment 1 Josh Bressers 2005-04-06 20:51:55 UTC
This issue also affects FC2

Comment 2 Than Ngo 2005-04-14 11:23:39 UTC
it's now fixed in sharutils-4.2.1-22.2.FC3 and sharutils-4.2.1-18.2.FC2

Comment 4 Marius Andreiana 2005-08-20 07:32:39 UTC
FC3 updates are out, FC2 is no longer supported.


Note You need to log in before you can comment on or make changes to this bug.