Gentoo Archives: gentoo-announce

From: Alex Legler <a3li@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200909-10 ] LMBench: Insecure temporary file usage
Date: Wed, 09 Sep 2009 14:06:48
Message-Id: 20090909152316.4a6c4083@neon
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200909-10
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: LMBench: Insecure temporary file usage
9 Date: September 09, 2009
10 Bugs: #246015
11 ID: 200909-10
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple insecure temporary file usage issues have been reported in
19 LMBench, allowing for symlink attacks.
20
21 Background
22 ==========
23
24 LMBench is a suite of simple, portable benchmarks for UNIX platforms.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 app-benchmarks/lmbench <= 3 Vulnerable!
33 -------------------------------------------------------------------
34 NOTE: Certain packages are still vulnerable. Users should migrate
35 to another package if one is available or wait for the
36 existing packages to be marked stable by their
37 architecture maintainers.
38
39 Description
40 ===========
41
42 Dmitry E. Oboukhov reported that the rccs and STUFF scripts do not
43 handle "/tmp/sdiff.#####" temporary files securely. NOTE: There might
44 be further occurances of insecure temporary file usage.
45
46 Impact
47 ======
48
49 A local attacker could perform symlink attacks to overwrite arbitrary
50 files with the privileges of the user running the application.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 LMBench has been removed from Portage. We recommend that users unmerge
61 LMBench:
62
63 # emerge --unmerge app-benchmarks/lmbench
64
65 References
66 ==========
67
68 [ 1 ] CVE-2008-4968
69 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4968
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-200909-10.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 https://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2009 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature