mktemp-generated filenames insufficiently random when too short

Bug #258172 reported by Till Ulen
252
Affects Status Importance Assigned to Milestone
mktemp (Debian)
Fix Released
Unknown
mktemp (Ubuntu)
Fix Released
Low
Unassigned

Bug Description

Binary package hint: mktemp

mktemp produces filenames that are partly not random, possibly allowing to mount a local attack.
Please see the discussion in Debian bug http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495193

Revision history for this message
Kees Cook (kees) wrote :

This is at most a DoS, as mktemp safely creates the random file for us. In the case that an attacker has filled the drive with all possible combinations, mktemp will just fail to create the file, and scripts using mktemp should equally fail. If there are scripts that don't gracefully handle mktemp failing, bugs should be opened for those packages separately.

Changed in mktemp:
importance: Undecided → Low
status: New → Confirmed
Changed in mktemp:
status: Unknown → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This is in Jaunty now:

mktemp (1.5-9) unstable; urgency=high

  * Upstream patch to remove pid from name generation. closes: #495193.

Changed in mktemp:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.