Activity log for bug #805370

Date Who What changed Old value New value Message
2011-07-04 09:07:45 David bug added bug
2011-07-04 15:51:08 David summary /usr/bin/getweb is rather hillarious -- and is vulnerable to "Insecure temporary file creation" weaknesses /usr/bin/getweb is vulnerable to "Insecure temporary file creation" weaknesses
2011-07-04 15:51:15 David description /usr/bin/getweb is vulnerable to "Insecure temporary file creation". [0] While I don't know if anyone uses the getweb command. The script makes a temporary directory in /tmp called foo2zjs it then may download (depending on user input) one or more gzip and extract them in /tmp/foo2zjs. However, the script does not check if the folder already exists / the return code of mkdir - so the script could possibly result in the over-writing of files or simply extra junk placed in $random places on the file-system. [0] - http://cwe.mitre.org/data/definitions/377.html [1] line 488 " mkdir -p /tmp/foo2zjs cd /tmp/foo2zjs " /usr/bin/getweb is vulnerable to "Insecure temporary file creation". [0] While I don't know if anyone uses the getweb command. The script makes a temporary directory in /tmp called foo2zjs it then may download (depending on user input) one or more gzip and extract them in /tmp/foo2zjs. However, the script does not check if the folder already exists / the return code of mkdir - so the script could possibly result in the over-writing of files or simply extra junk placed in $random places on the file-system. [0] - http://cwe.mitre.org/data/definitions/377.html [1] line 488 " mkdir -p /tmp/foo2zjs cd /tmp/foo2zjs "
2011-07-06 17:13:11 Marc Deslauriers visibility private public
2011-07-06 17:13:12 Marc Deslauriers bug added subscriber Ubuntu Bugs
2011-07-06 17:21:08 Marc Deslauriers foo2zjs (Ubuntu): status New Confirmed
2011-07-06 17:21:10 Marc Deslauriers foo2zjs (Ubuntu): importance Undecided Low
2011-07-12 19:13:49 Marc Deslauriers cve linked 2011-2684
2011-07-26 03:26:05 Launchpad Janitor branch linked lp:debian/foo2zjs
2011-07-27 22:40:11 Launchpad Janitor foo2zjs (Ubuntu): status Confirmed Fix Released