Bug 7465 - rpmdevtools new security issue CVE-2012-3500
Summary: rpmdevtools new security issue CVE-2012-3500
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 2
Hardware: i586 Linux
: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://lwn.net/Vulnerabilities/515830/
Whiteboard: MGA1TOO has_procedure MGA1-32-OK mga1...
Keywords: validated_update
Depends on:
Reported: 2012-09-12 21:55 CEST by David Walser
Modified: 2012-10-29 19:30 CET (History)
5 users (show)

See Also:
Source RPM: rpmdevtools-8.2-1.mga2.src.rpm
Status comment:


Description David Walser 2012-09-12 21:55:34 CEST
Fedora has issued an advisory on September 3:

Mageia 1 and Mageia 2 are also affected.

We should upgrade to 8.3 to fix this and other bugs.
Comment 1 David Walser 2012-10-16 19:30:21 CEST
Updated packages uploaded for Mageia 1, Mageia 2, and Cauldron.


Updated rpmdevtools package fixes security vulnerability:

A TOCTOU race condition was found in the way 'annotate-output' (used to
execute a program annotating the output linewise with time and stream) tool
of rpmdevtools before 8.3 performed management of its temporary files used
for standard output and standard error output. A local attacker could use
this flaw to conduct symbolic link attacks, possibly leading to their
ability in an unauthorized way to alter files belonging to the user running
the 'annotate-output' tool (CVE-2012-3500).


Updated packages in core/updates_testing:

from SRPMS:
Comment 2 Samuel Verschelde 2012-10-18 22:46:43 CEST
For Mageia 1, the version jump changes more than just the annotate-output fix, but given that this tool is just targeted at packagers and not required by a lot of packages (and apparently not required at all as a build dependency), ok with pushing version 8.3 to Mageia 1.

I tested some of the commands among those provided by the package, including annotate-output.

Comprehensive list of commands:
Comment 3 claire robinson 2012-10-24 12:17:21 CEST
rpmdiff shows these bin's changed

S.5........ /usr/bin/annotate-output
S.5........ /usr/bin/checkbashisms
S.5........ /usr/bin/licensecheck
..5........ /usr/bin/manpage-alert
S.5........ /usr/bin/rpmdev-bumpspec
S.5........ /usr/bin/rpmdev-newspec
S.5........ /usr/bin/rpmdev-setuptree

Testing with some of these. The CVE applies to annotate-output.

$ annotate-output cat /etc/release
10:44:56 I: Started cat /etc/release
10:44:56 O: Mageia release 2 (Official) for i586
10:44:56 I: Finished with exitcode 0

$ annotate-output cat /etc/release
10:46:56 I: Started cat /etc/release
10:46:56 O: Mageia release 2 (Official) for i586
10:46:56 I: Finished with exitcode 0

Testing some others..

$ checkbashisms -f ~/depcheck

shows alot of possible bashisms..(no comment :P)

$ manpage-alert .
No manual entry for ./21323.c
No manual entry for ./examplesh
No manual entry for ./gpl-3.0.txt
No manual entry for ./index.html

Downloaded the plain text gpl from http://www.gnu.org/licenses/gpl.html

$ licensecheck gpl-3.0.txt
gpl-3.0.txt: UNKNOWN

Maybe some problem there, otherwise OK.
Comment 4 claire robinson 2012-10-29 18:02:43 CET
testing complete mga2 64
Comment 5 claire robinson 2012-10-29 19:05:28 CET
testing complete mga1 64


Advisory and srpms in comment 1

Could sysadmin please push from core/updates_testing to core/updates

Comment 6 Thomas Backlund 2012-10-29 19:30:59 CET
Update pushed:

Note You need to log in before you can comment on or make changes to this bug.