[CVE-2007-2837] Unsafe tmp file handling

Bug #124725 reported by Michael Bienia
256
Affects Status Importance Assigned to Milestone
fireflier (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
Unassigned
Edgy
Won't Fix
Undecided
Unassigned
Feisty
Fix Released
Undecided
Unassigned

Bug Description

Here is a debdiff for feisty. This is a fireflier 1.1.6-3etch1 package with a Ubuntu changelog and changed Maintainer field.

fireflier (1.1.6-3ubuntu0.1) feisty-security; urgency=low

  * SECURITY UPDATE: Unsafe tmp file handling
  * Patch taken from fireflier 1.1.6-3etch1:
    Fix the unsafe usage of temporary files, allowing arbitary file deletion.
  * References:
    DSA-1326
    CVE-2007-2837
  * debian/control: Modify Maintainer value to match
    DebianMaintainerField spec.

 -- Michael Bienia <email address hidden> Sun, 08 Jul 2007 00:07:31 +0200

CVE References

Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :

Here is a debdiff for dapper.

dapper and edgy have the same version so one could apply the debdiff also to the edgy package but I've got problems building the edgy package in a pbuilder.

Michael Bienia (geser)
Changed in fireflier:
status: New → Fix Released
status: New → Confirmed
status: New → Confirmed
status: New → Confirmed
Revision history for this message
Michael Bienia (geser) wrote :

Updated debdiff for feisty:
use mkdir -m 0700

Revision history for this message
Michael Bienia (geser) wrote :

The same for dapper-security

Revision history for this message
Kees Cook (kees) wrote :

These have been published now. Thanks!

Changed in fireflier:
status: Confirmed → Fix Released
status: Confirmed → Fix Released
Revision history for this message
Hew (hew) wrote :

Ubuntu Edgy Eft is no longer supported, so a SRU will not be issued for this release. Marking Edgy as Won't Fix.

Changed in fireflier:
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.