Bug 208483 (CVE-2008-1694) - CVE-2008-1694 emacs insecure /tmp file usage
Summary: CVE-2008-1694 emacs insecure /tmp file usage
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2008-1694
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-09-28 20:03 UTC by Steve Grubb
Modified: 2019-09-29 12:19 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-02-17 15:09:50 UTC


Attachments (Terms of Use)
Patch fixing tmp file usage (565 bytes, patch)
2006-09-28 20:03 UTC, Steve Grubb
no flags Details | Diff

Description Steve Grubb 2006-09-28 20:03:24 UTC
Description of problem:
vcdiff script writes to a predictable tmp file. This could be used for attack by
malicious user.

Comment 1 Steve Grubb 2006-09-28 20:03:24 UTC
Created attachment 137341 [details]
Patch fixing tmp file usage

Comment 2 Lubomir Kundrak 2008-04-08 12:02:11 UTC
PATH=$PATH:/usr/ccs/bin:/usr/sccs:/usr/xpg4/bin # common SCCS hangouts

I don't like this either, it's unnecessary, but most likely has no security
consequences.

CVE Name was requested. Unless anyone objects, this will get public on Friday.
Chip, please communicate this upstream, and tell them not to commit fix until
friday.

Comment 3 Lubomir Kundrak 2008-04-08 16:04:54 UTC
CVE-2008-1694

Comment 9 Vincent Danen 2015-02-17 15:09:50 UTC
This issue was fixed prior to the GA releases of RHEL6 and 7.

Statement:

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.


Note You need to log in before you can comment on or make changes to this bug.