|
Mantis - GCC-XML
|
|||||
| Viewing Issue Advanced Details | |||||
|
|
|||||
| ID: | Category: | Severity: | Reproducibility: | Date Submitted: | Last Update: |
| 8083 | minor | always | 2008-11-12 15:34 | 2009-09-22 09:17 | |
|
|
|||||
| Reporter: | Craig_G | Platform: | |||
| Assigned To: | Brad King | OS: | |||
| Priority: | normal | OS Version: | |||
| Status: | closed | Product Version: | |||
| Product Build: | Resolution: | fixed | |||
| Projection: | none | ||||
| ETA: | none | Fixed in Version: | |||
|
|
|||||
| Summary: | 0008083: MIPSpro/find_flags symlink attack vector (CVE-2008-4957) | ||||
| Description: |
CVE-2008-4957 Published: 05-11-2008 Updated: 07-11-2008 Product: gccxml: gccxml 0.9.0 Severity: Medium (6.9) CVSS vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C) Attack`s vector: Localy exploitable Potential loss type: Integrity, Confidentiality, Availability Vulnerability description: find_flags in gccxml 0.9.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.cxx temporary file. There are more issues: Sun/find_flags: cat > "/tmp/gccxml_identify_compiler$GCCXML_PID.cc" <<! gccxml_find_flags: cat > "/tmp/gccxml_identify_compiler$GCCXML_PID.cc" <<! |
||||
| Steps To Reproduce: | |||||
| Additional Information: | These are confirmed to work, there is a suggested fix in: https://bugs.gentoo.org/show_bug.cgi?id=245765 [^] | ||||
| Relationships | |||||
| Attached Files: | |||||
|
|
|||||
| Issue History | |||||
| Date Modified | Username | Field | Change | ||
| 2008-11-12 15:34 | Craig_G | New Issue | |||
| 2008-11-12 15:42 | Brad King | Note Added: 0014094 | |||
| 2008-12-15 15:28 | Brad King | Note Added: 0014351 | |||
| 2008-12-15 15:29 | Brad King | Status | new => closed | ||
| 2008-12-15 15:29 | Brad King | Resolution | open => fixed | ||
| 2009-09-22 08:45 | Brad King | Status | closed => assigned | ||
| 2009-09-22 08:45 | Brad King | Assigned To | => Brad King | ||
| 2009-09-22 08:55 | Brad King | Note Added: 0017694 | |||
| 2009-09-22 09:16 | Brad King | Note Added: 0017695 | |||
| 2009-09-22 09:17 | Brad King | Status | assigned => closed | ||
| Notes | |||||
|
|
|||||
|
|
||||
|
|
|||||
|
|
||||
|
|
|||||
|
|
||||
|
|
|||||
|
|
||||