Bug 675811 - /tmp symlink vulnerability
Summary: /tmp symlink vulnerability
Keywords:
Status: CLOSED DUPLICATE of bug 676389
Alias: None
Product: Fedora
Classification: Fedora
Component: feh
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Ignacio Vazquez-Abrams
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-02-07 20:39 UTC by Andrew Potter
Modified: 2011-02-09 22:19 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-02-09 22:19:56 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Launchpad 607328 None None None Never
Debian BTS 612035 None None None Never

Description Andrew Potter 2011-02-07 20:39:23 UTC
Description of problem:
      tmpname_timestamper =
         estrjoin("", "/tmp/feh_", cppid, "_", basename, NULL);
...
            execlp("wget", "wget", "-N", "-O", tmpname_timestamper, newurl,
                   quiet, (char*) NULL);

If attacker knows PID of feh and knows the URL, it can create the link to any user file. wget would overwrite it.


https://bugs.launchpad.net/ubuntu/+source/feh/+bug/607328
https://github.com/derf/feh/issues/#issue/32

Comment 1 Vincent Danen 2011-02-09 22:19:56 UTC

*** This bug has been marked as a duplicate of bug 676389 ***


Note You need to log in before you can comment on or make changes to this bug.