summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCarsten Lohrke <carlo@gentoo.org>2005-08-14 23:33:39 +0000
committerCarsten Lohrke <carlo@gentoo.org>2005-08-14 23:33:39 +0000
commit44145f0749e7840ab9eb7ed5d1b248a01dbb20de (patch)
tree1b3f0b51495cb126e946cfd51dbddb14d9e239e7 /kde-base/kdeedu/files
parenttemp file vulnerability, #102151 (diff)
downloadgentoo-2-44145f0749e7840ab9eb7ed5d1b248a01dbb20de.tar.gz
gentoo-2-44145f0749e7840ab9eb7ed5d1b248a01dbb20de.tar.bz2
gentoo-2-44145f0749e7840ab9eb7ed5d1b248a01dbb20de.zip
KVoctrain temp file vulnerability, #102151
(Portage version: 2.0.51.22-r2)
Diffstat (limited to 'kde-base/kdeedu/files')
-rw-r--r--kde-base/kdeedu/files/digest-kdeedu-3.3.2-r22
-rw-r--r--kde-base/kdeedu/files/digest-kdeedu-3.4.1-r11
-rw-r--r--kde-base/kdeedu/files/digest-kdeedu-3.4.1-r111
-rw-r--r--kde-base/kdeedu/files/digest-kdeedu-3.4.2-r21
-rw-r--r--kde-base/kdeedu/files/post-3.4.2-kdeedu.diff63
5 files changed, 68 insertions, 0 deletions
diff --git a/kde-base/kdeedu/files/digest-kdeedu-3.3.2-r2 b/kde-base/kdeedu/files/digest-kdeedu-3.3.2-r2
new file mode 100644
index 000000000000..0f4c0506d9ad
--- /dev/null
+++ b/kde-base/kdeedu/files/digest-kdeedu-3.3.2-r2
@@ -0,0 +1,2 @@
+MD5 2ea54bb7aee669582eb0877d3c6f0b3d kdeedu-3.3.2.tar.bz2 22069753
+MD5 d8c1e43263124b4ef17cbf1b368a4f9f kstars-3_3.diff.tar.gz 13701
diff --git a/kde-base/kdeedu/files/digest-kdeedu-3.4.1-r1 b/kde-base/kdeedu/files/digest-kdeedu-3.4.1-r1
new file mode 100644
index 000000000000..2d593459a047
--- /dev/null
+++ b/kde-base/kdeedu/files/digest-kdeedu-3.4.1-r1
@@ -0,0 +1 @@
+MD5 9fa1db1cf500c0fc594b0f5d291bbf69 kdeedu-3.4.1.tar.bz2 24009520
diff --git a/kde-base/kdeedu/files/digest-kdeedu-3.4.1-r11 b/kde-base/kdeedu/files/digest-kdeedu-3.4.1-r11
new file mode 100644
index 000000000000..2d593459a047
--- /dev/null
+++ b/kde-base/kdeedu/files/digest-kdeedu-3.4.1-r11
@@ -0,0 +1 @@
+MD5 9fa1db1cf500c0fc594b0f5d291bbf69 kdeedu-3.4.1.tar.bz2 24009520
diff --git a/kde-base/kdeedu/files/digest-kdeedu-3.4.2-r2 b/kde-base/kdeedu/files/digest-kdeedu-3.4.2-r2
new file mode 100644
index 000000000000..733395bad924
--- /dev/null
+++ b/kde-base/kdeedu/files/digest-kdeedu-3.4.2-r2
@@ -0,0 +1 @@
+MD5 e2c5cc083868dd4c35c1b50e04eb40eb kdeedu-3.4.2.tar.bz2 24028133
diff --git a/kde-base/kdeedu/files/post-3.4.2-kdeedu.diff b/kde-base/kdeedu/files/post-3.4.2-kdeedu.diff
new file mode 100644
index 000000000000..1d75c63bac18
--- /dev/null
+++ b/kde-base/kdeedu/files/post-3.4.2-kdeedu.diff
@@ -0,0 +1,63 @@
+Index: kvoctrain/kvoctrain/langen2kvtml
+===================================================================
+--- kvoctrain/kvoctrain/langen2kvtml (revision 443975)
++++ kvoctrain/kvoctrain/langen2kvtml (working copy)
+@@ -89,6 +89,9 @@
+
+ require "flush.pl";
+ use Getopt::Long;
++use File::Temp qw(tempdir);
++my $tmpdir = tempdir(TEMPDIR => 1, CLEANUP => 1 );
++
+ $/="\r\n"; # we work with dos files
+
+ #
+@@ -165,10 +168,6 @@
+ $country="GB";
+ }
+
+-# All logging information goes into this file
+-$logfile = "/tmp/langen2kvtml.log";
+-open(LOG, ">$logfile") || die "Cannot create $logfile: $!";
+-
+ &printflush(STDOUT,"Waiting for generating files ...\n");
+ $tmp1=$#ARGV+1;
+ &printflush(STDOUT,"... $tmp1 files given via command line ...\n");
+@@ -178,13 +177,11 @@
+ if ($proxy) {
+ &printflush(STDOUT,"... using proxy service $proxy ...\n");
+ }
+- `lwp-request $proxy http://www.vokabeln.de/files/Voc-$country.zip >/tmp/Voc-$country.zip`;
+- # unzip -u update only!
+- # unzip -o overwrite!
+- `unzip -u /tmp/Voc-$country.zip >/tmp/unzip.log`;
++ `lwp-request $proxy http://www.vokabeln.de/files/Voc-$country.zip >$tmpdir/Voc-$country.zip`;
+ &printflush(STDOUT,"... updating Voc-$country.zip ...\n");
+ $/="\n"; # we work with a unix file
+- open(ZIP,"</tmp/unzip.log");
++ # unzip -u update only!
++ open(ZIP,"unzip -u $tmpdir/Voc-$country.zip |");
+ while(<ZIP>) {
+ chomp;
+ if( /voc/ ) {
+@@ -194,20 +191,16 @@
+ }
+ }
+ close(ZIP);
+- unlink("/tmp/unzip.log");
+ $/="\r\n"; # we work with a dos file
+ }
+
+ for my $file (@res, @ARGV) {
+ $vocfile = $file;
+- &printflush(LOG,"... generating \"$kvtfile\"...\n");
+ $lang = ""; # initially unset
+ $filestage = 0; # file stage
+ &process_vocfile($vocfile);
+ }
+ print STDERR "...\tAll Complete.\n";
+-&printflush(LOG,"\nAll Complete.\n");
+-close(LOG);
+
+ exit;
+