Kile uses default permissions for backup files, potentially leading to information disclosure.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200611-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Kile: Incorrect backup file permission Date: November 27, 2006 Bugs: #155613 ID: 200611-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Kile uses default permissions for backup files, potentially leading to information disclosure. Background ========= Kile is a TeX/LaTeX editor for KDE. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-editors/kile < 1.9.2-r1 > = 1.9.2-r1 Description ========== Kile fails to set the same permissions on backup files as on the original file. This is similar to CVE-2005-1920. Impact ===== A kile user may inadvertently grant access to sensitive information. Workaround ========= There is no known workaround at this time. Resolution ========= All Kile users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-editors/kile-1.9.2-r1" References ========= [ 1 ] CVE-2005-1920 https://www.cve.org/CVERecord?id=CVE-2005-1920 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200611-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Anysecurity concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.