OpenPKG Corporation
OpenPKG CorporationSecuritySecurity Advisories

OpenPKG Security Advisory

OpenPKG-SA-2007.002

Publisher Name:          OpenPKG GmbH
Publisher Home:          http://openpkg.com/

Advisory Id (public):    OpenPKG-SA-2007.002
Advisory Type:           OpenPKG Security Advisory (SA)
Advisory Directory:      http://openpkg.com/go/OpenPKG-SA
Advisory Document:       http://openpkg.com/go/OpenPKG-SA-2007.002
Advisory Published:      2010-02-09 20:14 UTC

Issue Id (internal):     OpenPKG-SI-20070105.01
Issue First Created:     2007-01-05
Issue Last Modified:     2007-01-05
Issue Revision:          04


Subject Name: bzip2 Subject Summary: Compression Tool Subject Home: http://www.bzip.org/ Subject Versions: * <= 1.0.3 Vulnerability Id: CVE-2005-0953, CVE-2005-0758 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: local system Attack Impact: manipulation of data, arbitrary code execution Description: Together with two portability and stability issues, two older security issues were fixed in the compression tool BZip2 [0], versions up to and including 1.0.3. The first issue is a race condition which allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete. The second issue affects the script bzgrep(1). It does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed(1) script. References: [0] http://www.bzip.org/
Primary Package Name: bzip2 Primary Package Home: http://openpkg.org/go/package/bzip2 Affected Distribution: Affected Branch: Affected Package: OpenPKG Enterprise E1.0-SOLID bzip2-1.0.3-E1.0.0 OpenPKG Enterprise E1.0-SOLID openpkg-E1.0.1-E1.0.1 OpenPKG Community 2-STABLE-20061018 bzip2-1.0.3-2.20061018 OpenPKG Community 2-STABLE-20061018 openpkg-2.20061210-2.20061210 OpenPKG Community 2-STABLE bzip2-1.0.3-2.20061022 OpenPKG Community 2-STABLE openpkg-2.20061210-2.20061210 OpenPKG Community CURRENT bzip2-1.0.3-20061022 OpenPKG Community CURRENT openpkg-20070102-20070102 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Enterprise E1.0-SOLID bzip2-1.0.3-E1.0.1 OpenPKG Enterprise E1.0-SOLID openpkg-E1.0.2-E1.0.2 OpenPKG Community 2-STABLE-20061018 bzip2-1.0.4-2.20070105 OpenPKG Community 2-STABLE-20061018 openpkg-2.20070105-2.20070105 OpenPKG Community 2-STABLE bzip2-1.0.4-2.20070105 OpenPKG Community 2-STABLE openpkg-2.20070105-2.20070105 OpenPKG Community CURRENT bzip2-1.0.4-20070105 OpenPKG Community CURRENT openpkg-20070105-20070105

Latest Advisories:
2007.023 perl
2007.022 bind
2007.021 wordpress
2007.020 php
2007.019 php
2007.018 freetype
2007.017 ratbox
2007.016 gd
2007.015 quagga
2007.014 bind
more...

See Also:
OpenPKG Enterprise 1
ChangeLog!

Validation: XHTML | CSS