#33150 [Opn->Asn]: shtool php insecure temporary file creation
| From: | sniper@php.net | Date: | Sun, 29 May 2005 23:02:06 +0000 |
| Subject: | #33150 [Opn->Asn]: shtool php insecure temporary file creation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-79669@lists.php.net to get a copy of this message | ||
ID: 33150
Updated by: sniper@php.net
Reported By: eromang at zataz dot net
-Status: Open
+Status: Assigned
-Bug Type: Unknown/Other Function
+Bug Type: Compile Failure
Operating System: UNIX
-PHP Version: 4.3.11
+PHP Version: 5.*, 4.*
-Assigned To:
+Assigned To: sniper
New Comment:
We'll update the bundled shtool as soon as they release new version of
it. We will not start patching it ourselves.
Previous Comments:
------------------------------------------------------------------------
[2005-05-29 22:25:54] eromang at zataz dot net
Hello,
Here under the patch proposal from Gentoo Security Team.
https://bugs.gentoo.org/attachment.cgi?id=60117
CAN-2005-1751
Regards.
------------------------------------------------------------------------
[2005-05-29 12:48:25] koon at gentoo dot org
shtool in PHP snapshot is still affected.
Note that the proposed patch is probably not sufficient, stay tuned for
more.
------------------------------------------------------------------------
[2005-05-26 14:59:09] tony2001@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
------------------------------------------------------------------------
[2005-05-26 13:56:00] eromang at zataz dot net
suggested fix:
- tmpfile="$tmpdir/.shtool.$$"
- rm -f $tmpfile >/dev/null 2>&1
- touch $tmpfile
- chmod 600 $tmpfile
+ tmpfile=
mktemp "$tmpdir/.shtool.XXXXXX"
------------------------------------------------------------------------
[2005-05-26 13:43:40] eromang at zataz dot net
Description:
------------
Hello,
php is using a vulnerable version of shtool.
For more informations :
http://www.securityfocus.com/bid/13767?ref=rss
Regards
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=33150&edit=1