Bug 118182

Summary: VUL-0: arc insecure temp file creation
Product: [openSUSE] SUSE Linux 10.1 Reporter: Thomas Biege <thomas>
Component: OtherAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P5 - None CC: patch-request, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: All   
Whiteboard: CVE-2005-2992: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: patch.CAN-2005-2945.arc

Description Thomas Biege 2005-09-21 08:11:10 UTC
Hello,
I have some bugs for you.

-----------------------------------------------------------------------
Two vulnerabilities have been discovered in the ARC archive program
under Unix.  The Common Vulnerabilities and Exposures project
identifies the following problems:

CAN-2005-2945

    Eric Romang discovered that the ARC archive program under Unix
    creates a temporary file with insecure permissions which may lead
    to an attacker stealing sensitive information.

CAN-2005-2992

    Joey Schulze discovered that the temporary file was created in an
    insecure fashion as well, leaving it open to a classic symlink
    attack.
Comment 1 Stanislav Brabec 2005-09-21 13:09:36 UTC
We dropped arc before 9.3. Should I create YOU update? Is there any patch?
Comment 2 Thomas Biege 2005-09-21 14:09:07 UTC
Good we dropped it.
I suspect that arc is used by other tools automatically (virii scanner, email
clients, ...), therefore an update for older versions would be good.
Comment 3 Thomas Biege 2005-09-21 14:10:02 UTC
Created attachment 50539 [details]
patch.CAN-2005-2945.arc
Comment 4 Stanislav Brabec 2005-09-21 15:03:58 UTC
Fixed package submitted for sles8, 9.0, 9.1 and 9.2.
Comment 5 Thomas Biege 2005-09-26 12:27:43 UTC
Maintenance-Tracker-2382
Comment 6 Thomas Biege 2005-09-26 12:37:39 UTC
/work/src/done/PATCHINFO/arc.patch.{box,maintained}
Comment 7 Thomas Biege 2005-09-27 12:49:07 UTC
packages released
Comment 8 Thomas Biege 2009-10-13 21:35:50 UTC
CVE-2005-2992: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N)