[Linux-wlan-ng-devel] Bug#290047: marked as done (linux-wlan-ng: insecure /tmp usage)

Debian Bug Tracking System owner at bugs.debian.org
Sat Nov 5 16:03:09 UTC 2005


Your message dated Sat, 5 Nov 2005 16:50:19 +0100
with message-id <20051105155019.GA23145 at garfield>
and subject line fixed in NMU a million of years ago
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 12 Jan 2005 15:51:11 +0000
>From erno-debbugs at erno.iki.fi Wed Jan 12 07:51:11 2005
Return-path: <erno-debbugs at erno.iki.fi>
Received: from fabulous.u--3.com (erno.iki.fi) [213.139.167.121] (postfix)
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1Cokm7-0002F7-00; Wed, 12 Jan 2005 07:51:11 -0800
Received: by erno.iki.fi (Postfix, from userid 1000)
	id A4943188728; Wed, 12 Jan 2005 17:51:08 +0200 (EET)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Erno Kuusela <erno-debbugs at erno.iki.fi>
To: Debian Bug Tracking System <submit at bugs.debian.org>
Subject: linux-wlan-ng: insecure /tmp usage
X-Mailer: reportbug 3.5
Date: Wed, 12 Jan 2005 17:51:08 +0200
Message-Id: <20050112155108.A4943188728 at erno.iki.fi>
Delivered-To: submit at bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: linux-wlan-ng
Severity: critical
Tags: security
Justification: root security hole


% mkdir t
% dpkg-deb -x linux-wlan-ng_0.2.0+0.2.1pre21-1_i386.deb t                
% grep -r /tmp/ t/etc
t/etc/apm/resume.d/linux-wlan-ng-resume:        echo down $ifcase >>/tmp/log
t/etc/wlan/shared:              cp $WLAN_SCHEMEFILE /tmp/wlan_scheme_`date +"%T"`.tmp
t/etc/wlan/shared:              touch /tmp/wlan_scheme_`date +"%T"`.tmp
t/etc/wlan/shared:      TMPFILE=`ls /tmp/wlan_scheme*.tmp | tail -n 1`


-- System Information:
Debian Release: 3.0
  APT prefers unstable
  APT policy: (50, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.10-rc3
Locale: LANG=C, LC_CTYPE=fi_FI (charmap=ISO-8859-1)

---------------------------------------
Received: (at 290047-done) by bugs.debian.org; 5 Nov 2005 15:50:52 +0000
>From gareuselesinge at virgilio.it Sat Nov 05 07:50:52 2005
Return-path: <gareuselesinge at virgilio.it>
Received: from host82-126.pool80180.interbusiness.it (host85-126.pool80180.interbusiness.it) [80.180.126.82] 
	by spohr.debian.org with esmtp (Exim 3.36 1 (Debian))
	id 1EYQJg-00078g-00; Sat, 05 Nov 2005 07:50:52 -0800
Received: from garfield.casa-tassi ([192.168.0.1] helo=localhost.localdomain)
	by host85-126.pool80180.interbusiness.it with esmtp (Exim 3.36 #1 (Debian))
	id 1EYQOq-0007G5-00
	for <290047-done at bugs.debian.org>; Sat, 05 Nov 2005 16:56:12 +0100
Received: from tassi by localhost.localdomain with local (Exim 4.54)
	id 1EYQJ9-0006Aw-V4
	for 290047-done at bugs.debian.org; Sat, 05 Nov 2005 16:50:19 +0100
Date: Sat, 5 Nov 2005 16:50:19 +0100
From: Enrico Tassi <gareuselesinge at users.sourceforge.net>
To: 290047-done at bugs.debian.org
Subject: fixed in NMU a million of years ago
Message-ID: <20051105155019.GA23145 at garfield>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.5.11
Delivered-To: 290047-done at bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-2.5 required=4.0 tests=BAYES_00,RCVD_IN_SORBS 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02

nothing to say
-- 
Enrico Tassi




More information about the Linux-wlan-ng-devel mailing list