#33150 [Asn->Csd]: shtool: insecure temporary file creation
ID: 33150
Updated by: sniper@php.net
Reported By: eromang at zataz dot net
-Status: Assigned
+Status: Closed
Bug Type: Compile Failure
Operating System: UNIX
PHP Version: 5.*, 4.*
Assigned To: sniper
New Comment:
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2005-06-18 20:57:32] sniper@php.net
We use the 'path' command also, and that one is affected.
------------------------------------------------------------------------
[2005-06-10 17:18:20] koon at gentoo dot org
Apparently PHP only uses the mkdir and echo commands, neither makes a
tmpfile. SO you probably aren't affected by this currently.
------------------------------------------------------------------------
[2005-05-30 01:02:05] sniper@php.net
We'll update the bundled shtool as soon as they release new version of
it. We will not start patching it ourselves.
------------------------------------------------------------------------
[2005-05-29 22:25:54] eromang at zataz dot net
Hello,
Here under the patch proposal from Gentoo Security Team.
https://bugs.gentoo.org/attachment.cgi?id=60117
CAN-2005-1751
Regards.
------------------------------------------------------------------------
[2005-05-26 13:43:40] eromang at zataz dot net
Description:
------------
Hello,
php is using a vulnerable version of shtool.
For more informations :
http://www.securityfocus.com/bid/13767?ref=rss
Regards
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=33150&edit=1
Thread (9 messages)