Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200804-29 ] Comix: Multiple vulnerabilities
Date: Fri, 25 Apr 2008 21:09:23
Message-Id: 481241F8.6060201@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200804-29
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Comix: Multiple vulnerabilities
12 Date: April 25, 2008
13 Bugs: #215694
14 ID: 200804-29
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities in Comix may lead to execution of arbitrary
22 commands and a Denial of Service.
23
24 Background
25 ==========
26
27 Comix is a GTK comic book viewer.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 media-gfx/comix < 3.6.4-r1 >= 3.6.4-r1
36
37 Description
38 ===========
39
40 Comix does not properly sanitize filenames containing shell
41 metacharacters when they are passed to the rar, unrar, or jpegtran
42 programs (CVE-2008-1568). Comix also creates directories with
43 predictable names (CVE-2008-1796).
44
45 Impact
46 ======
47
48 A remote attacker could exploit the first vulnerability by enticing a
49 user to use Comix to open a file with a specially crafted filename,
50 resulting in the execution of arbitrary commands. The second
51 vulnerability could be exploited by a local attacker to cause a Denial
52 of Service by creating a file or directory with the same filename as
53 the predictable filename used by Comix.
54
55 Workaround
56 ==========
57
58 There is no known workaround at this time.
59
60 Resolution
61 ==========
62
63 All Comix users should upgrade to the latest version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose ">=media-gfx/comix-3.6.4-r1"
67
68 References
69 ==========
70
71 [ 1 ] CVE-2008-1568
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1568
73 [ 2 ] CVE-2008-1796
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1796
75
76 Availability
77 ============
78
79 This GLSA and any updates to it are available for viewing at
80 the Gentoo Security Website:
81
82 http://security.gentoo.org/glsa/glsa-200804-29.xml
83
84 Concerns?
85 =========
86
87 Security is a primary focus of Gentoo Linux and ensuring the
88 confidentiality and security of our users machines is of utmost
89 importance to us. Any security concerns should be addressed to
90 security@g.o or alternatively, you may file a bug at
91 http://bugs.gentoo.org.
92
93 License
94 =======
95
96 Copyright 2008 Gentoo Foundation, Inc; referenced text
97 belongs to its owner(s).
98
99 The contents of this document are licensed under the
100 Creative Commons - Attribution / Share Alike license.
101
102 http://creativecommons.org/licenses/by-sa/2.5
103 -----BEGIN PGP SIGNATURE-----
104 Version: GnuPG v2.0.7 (GNU/Linux)
105 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
106
107 iD8DBQFIEkH4uhJ+ozIKI5gRAmiNAKCPHnfT5QvO2DSX5GLVFSktoJxuUwCdHQ7L
108 CsRRiV/a7lFJnuCxwl4Sg6E=
109 =DaV+
110 -----END PGP SIGNATURE-----
111 --
112 gentoo-announce@l.g.o mailing list