Bug 155749 - CVE-2005-1111 Race condition in cpio
CVE-2005-1111 Race condition in cpio
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: cpio (Show other bugs)
4.0
All Linux
medium Severity medium
: ---
: ---
Assigned To: Peter Vrabec
Brock Organ
impact=moderate,public=20050413,sourc...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-04-22 14:45 EDT by Josh Bressers
Modified: 2007-11-30 17:07 EST (History)
1 user (show)

See Also:
Fixed In Version: RHSA-2005:378
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-04-29 22:51:31 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Proposed patch from Steve Grubb (14.19 KB, patch)
2005-04-29 09:44 EDT, Mark J. Cox (Product Security)
no flags Details | Diff
I suggest to use this patch. (7.03 KB, patch)
2005-07-01 05:38 EDT, Peter Vrabec
no flags Details | Diff

  None (edit)
Description Josh Bressers 2005-04-22 14:45:45 EDT
Race condition in cpio 2.6 and earlier allows local users to modify permissions
of arbitrary files via a hard link attack on a file while it is being
decompressed, whose permissions are changed by cpio after the decompression is
complete.

http://marc.theaimsgroup.com/?l=bugtraq&m=111342664116120&w=2
Comment 1 Josh Bressers 2005-04-22 14:50:20 EDT
This issue should also affect RHEL2.1 and RHEL3.
Comment 2 Mark J. Cox (Product Security) 2005-04-29 09:44:08 EDT
Created attachment 113839 [details]
Proposed patch from Steve Grubb
Comment 3 Peter Vrabec 2005-07-01 05:38:30 EDT
Created attachment 116230 [details]
I suggest to use this patch.

Steve's patch doesn't solve race condition on directories. My fix use mode 0700
for dir creation, which close some more holes.
Comment 5 Josh Bressers 2005-09-30 11:05:31 EDT
We have not released an update for this issue on RHEL2.1 yet.  RHEL3 and RHEL4
were fixed in RHSA-2005:378
Comment 7 Bastien Nocera 2005-10-03 06:08:13 EDT
The RHEL 2.1 bug in being tracked in bug #169760

Note You need to log in before you can comment on or make changes to this bug.