FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

guile2 -- multiple vulnerabilities

Affected packages
guile2 < 2.0.13

Details

VuXML ID b4ecf774-eb01-11e6-9ac1-a4badb2f4699
Discovery 2016-10-12
Entry 2017-02-04

Ludovic Courtès reports:

The REPL server is vulnerable to the HTTP inter-protocol attack

The ‘mkdir’ procedure of GNU Guile, an implementation of the Scheme programming language, temporarily changed the process’ umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions.

References

CVE Name CVE-2016-8605
CVE Name CVE-2016-8606
FreeBSD PR ports/216663
URL http://www.openwall.com/lists/oss-security/2016/10/11/1
URL http://www.openwall.com/lists/oss-security/2016/10/12/2