Bug 48161 (CVE-2003-0887) - VUL-0: CVE-2003-0887: ez-ipupdate: tmp vulnerability
Summary: VUL-0: CVE-2003-0887: ez-ipupdate: tmp vulnerability
Status: RESOLVED FIXED
Alias: CVE-2003-0887
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Linux
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2003-0887: CVSS v2 Base Score: 2....
Keywords:
Depends on:
Blocks:
 
Reported: 2003-11-17 17:17 UTC by Thomas Biege
Modified: 2021-09-29 14:39 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2003-11-17 17:17:31 UTC
Hi, 
the following was posted to vendor-sec. 
Please, make the changes in our STABLE tree. 
Thank you! :)
Comment 1 Thomas Biege 2003-11-17 17:17:31 UTC
<!-- SBZ_reproduce  -->
Date: Sat, 15 Nov 2003 12:41:41 +0100 
From: Arjan van de Ven <arjanv@redhat.com> 
To: vendor-sec@lst.de 
Subject: [vendor-sec] ez-ipupdate package 
Parts/Attachments: 
   1 Shown    ~16 lines  Text 
   2          196 bytes  Application, "This is a digitally signed message part" 
---------------------------------------- 
 
Hi, 
 
The ez-ipupdate package by default comes with a set of example config 
files that put a fixed filename in /tmp while the binary that handles 
the file does nothing to even remotely do that safely. 
It seems that SUSE and Mandrake both ship this package. 
 
I've changed the location of the cache file to default to 
/var/cache/ez-ipupdate; I would suggest that anyone who ships this also 
changes the default locations in the configs to be not-in-/tmp. 
 
 
Greetings, 
   Arjan van de Ven
Comment 2 Hendrik Vogelsang 2003-11-17 21:25:41 UTC
btw the default conf file in /etc has 

cache-file=/var/lib/ez-ipupdate/ez-ipupdate.cache.ppp0

and /var/lib/ez-ipupdate is not world writeable.

i patched the example configs.
Comment 3 Thomas Biege 2004-06-01 19:40:23 UTC
CAN-2003-0887. 
I hope RH doesn't want to make a full blown update because of it... 
Comment 4 Thomas Biege 2009-10-13 19:41:44 UTC
CVE-2003-0887: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N)