| Summary: | geoip possibly security issue with symlink attacks due to predictable tmp filenames in cron job | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Mageia Bug Squad <bugsquad> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | dan, oe |
| Version: | 4 | ||
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | geoip-1.5.1-3.mga4.src.rpm | CVE: | |
| Status comment: | |||
Closing due to Mageia 3 EOL: http://blog.mageia.org/en/2014/11/26/lets-say-goodbye-to-mageia-3/ Status:
NEW =>
RESOLVED This is still an issue in mga4. Status:
RESOLVED =>
REOPENED No it isn't, due to symlink protection in the kernel. Those kinds of issues are no longer security concerns as of Mageia 4. Status:
REOPENED =>
RESOLVED That's great to know! I tested it and it does fix this issue. Version:
3 =>
4
Oden Eriksson
2014-11-28 09:31:07 CET
CC:
(none) =>
oe |
CC: (none) => dan