CVE-2016-8605
published 2017-01-12CVE-2016-8605: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could…
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
2.79%
84.8th percentile
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | guile | <= 2.0.12 | — |
| gnu | guile | >= 0 < 2.0.11-r3 | 2.0.11-r3 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jxp8-7966-cm98: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero
ghsa_unreviewed·2022-05-17
CVE-2016-8605 [MEDIUM] GHSA-jxp8-7966-cm98: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
OSV
CVE-2016-8605: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero
osv·2017-01-12·CVSS 5.3
CVE-2016-8605 [MEDIUM] CVE-2016-8605: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
Red Hat
guile: Thread-unsafe umask modification
vendor_redhat·2016-10-10·CVSS 5.3
CVE-2016-8605 [MEDIUM] guile: Thread-unsafe umask modification
guile: Thread-unsafe umask modification
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
A vulnerability was found in guile, in the mkdir procedure's usage of umask(2). Under particular circumstances, an attacker could influence an application written in guile to create directories or files insecurely, potentially exposing them to being read or manipulated by local users.
Statement: Red Hat Product Security has rated this issue as having Low security
impact. This issue is not currently
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8605 CVE-2016-8606 guile: various flaws [fedora-all]
bugzilla·2016-10-12·CVSS 5.3
CVE-2016-8605 [MEDIUM] CVE-2016-8605 CVE-2016-8606 guile: various flaws [fedora-all]
CVE-2016-8605 CVE-2016-8606 guile: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While on
Bugzilla
CVE-2016-8605 guile: Thread-unsafe umask modification
bugzilla·2016-10-12·CVSS 5.3
CVE-2016-8605 [MEDIUM] CVE-2016-8605 guile: Thread-unsafe umask modification
CVE-2016-8605 guile: Thread-unsafe umask modification
The mkdir procedure of GNU Guile, an implementation of the Scheme programming language, temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777.
Upstream bug:
http://debbugs.gnu.org/cgi/bugreport.cgi?bug=24659
Upstream patch:
http://git.savannah.gnu.org/cgit/guile.git/commit/?h=stable-2.0&id=245608911698adb3472803856019bdd5670b6614
References:
http://seclists.org/oss-sec/2016/q4/92
Discussion:
Created compat-guile18 tracking bugs for this issue:
Affects: fedora-all [bug 1383974]
Affects: epel-7 [bug 1383975]
---
Created gui
Bugzilla
CVE-2016-8605 CVE-2016-8606 compat-guile18: various flaws [fedora-all]
bugzilla·2016-10-12·CVSS 5.3
CVE-2016-8605 [MEDIUM] CVE-2016-8605 CVE-2016-8606 compat-guile18: various flaws [fedora-all]
CVE-2016-8605 CVE-2016-8606 compat-guile18: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2016-8605 CVE-2016-8606 compat-guile18: various flaws [epel-7]
bugzilla·2016-10-12·CVSS 5.3
CVE-2016-8605 [MEDIUM] CVE-2016-8605 CVE-2016-8606 compat-guile18: various flaws [epel-7]
CVE-2016-8605 CVE-2016-8606 compat-guile18: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion
http://www.openwall.com/lists/oss-security/2016/10/12/1http://www.securityfocus.com/bid/93510https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QTAGSDCTYXTABAA77BQJGNKOOBRV4DK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNVE5N24FLWDYBQ3LAFMF6BFCWKDO7VM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UJP5S36GTXMDEBXWF6LKKV76DSLNQG44/http://www.openwall.com/lists/oss-security/2016/10/12/1http://www.securityfocus.com/bid/93510https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QTAGSDCTYXTABAA77BQJGNKOOBRV4DK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNVE5N24FLWDYBQ3LAFMF6BFCWKDO7VM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UJP5S36GTXMDEBXWF6LKKV76DSLNQG44/
2017-01-12
Published