$NetBSD: patch-CVE-2005-3124,v 1.1 2026/09/25 14:20:39 wiz Exp $

CVE-2005-3124 -- the script wrote to /tmp/stc1.$$, a name that can be
worked out in advance, so anyone with write access to /tmp could put a
symlink there and have the script write through it.  Use mktemp(1) and
remove the file on the way out.  NVD says this was fixed before 2.23,
but 2.29 still has the /tmp name, which is why the patch is still here.

The line as written carried a stray second backtick, so the script it
produced did not parse -- "sh -n" reports an unmatched backtick, and
running it gives

  syslogtocern: 34: Syntax error: "||" unexpected

before it does anything.  That has been so since the patch was added in
2005, so the installed syslogtocern has never run.  Nobody was exposed
to the symlink attack by it, because a script that does not parse does
not write anywhere; the tool was simply dead.  With the backtick removed
it parses, keeps the mktemp(1) protection, and converts a syslog file
into CERN-format access_log and error_log as the manual page says.

--- extras/syslogtocern.orig	2005-05-20 19:10:25.000000000 +0000
+++ extras/syslogtocern
@@ -31,8 +31,8 @@
     exit 1
 fi
 
-tmp1=/tmp/stc1.$$
-rm -f $tmp1
+tmp1=`mktemp -t stc1.XXXXXX` || { echo "$0: Cannot create temporary file" >&2; exit 1;  }
+trap " [ -f \"$tmp1\" ] && /bin/rm -f -- \"$tmp1\"" 0 1 2 3 13 15
 
 # Gather up all the thttpd entries.
 egrep -h ' thttpd\[' "$@" > $tmp1
