Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in rdesktop
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in rdesktop
ID: USN-1136-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Mi, 25. Mai 2011, 20:20
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1595
Applikationen: rdesktop

Originalnachricht


--===============2510094876654923452==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature"; boundary="=-5WbwE8FE7AMCkY8g4Lgx"


--=-5WbwE8FE7AMCkY8g4Lgx
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1136-1
May 25, 2011

rdesktop vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

An attacker could access your files if rdesktop connected to a malicious
server.

Software Description:
- rdesktop: RDP client for Windows NT/2000 Terminal Server

Details:

It was discovered that rdesktop incorrectly handled specially crafted
paths when using disk redirection. If a user were tricked into connecting
to a malicious server, an attacker could access arbitrary files on the
user's filesystem.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
rdesktop 1.6.0-3ubuntu4.1

Ubuntu 10.10:
rdesktop 1.6.0-3ubuntu2.1

Ubuntu 10.04 LTS:
rdesktop 1.6.0-2ubuntu3.1

In general, a standard system update will make all the necessary changes.

References:
CVE-2011-1595

Package Information:
https://launchpad.net/ubuntu/+source/rdesktop/1.6.0-3ubuntu4.1
https://launchpad.net/ubuntu/+source/rdesktop/1.6.0-3ubuntu2.1
https://launchpad.net/ubuntu/+source/rdesktop/1.6.0-2ubuntu3.1



--ÕWbwE8FE7AMCkY8g4Lgx
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJN3T3MAAoJEGVp2FWnRL6TiDMP/2+Sjmwf0t6USVTDFFwLdtqP
BRjGXNv/PXuafT3wzW3vBZYxoLlOtNopdA05SqRYlwXA+cTb2SVhaEt3yo3AYrHg
Jm2W9bp134FGSi+x9+EYbg70WcDUKYk/TSw6ghXMcZ5CIjXJVVPO6qFK3bbEsu7e
DtHodBm0kmYgpTafH+SELzSr1AvBngdeB+7y6gJx5tEJL20EYBa+L9JcewVbY9qQ
F65gGWAwPd0lIkmed5EyQ5gjGG4RrfWZRsO5ZEPoGpV9zX7XKoboC6zS5xaXnsmr
fH7qJPNbLdt54EWeN1c2ExoVikO2vtSm88x+wIxpjVv6qbceoyxShXKnisnJ84G5
TxPnouhSC/3N1vac7w8e5vUZ7v6i7vo/s6PBo3Ma7VPhiEBpBSUT+fnFM4fQpeer
yD4ljlpuzdu6FQ8oQ1MjIXyl361GdHvkA8t33t06qMW9TI5nt6aG14DAZ/3YWgoH
BgU03T7tvNrpVd79Tm1b3q6VpKyuz6U1hK3fmIr4at4xgCvCsvKFhJdBIml6Zrxq
f0z6TOnIU4GoFEORsS7U4pO/Ufp1z0//JoASej5ZNzDUR93cc/532wPuPMqaBu9H
r/jVXUPFc4d+4mmbP/nqQ858pxCmHJpwoFtM3UPB7C5N3dO4veFtcBYLaBJ7G7xD
k8L5EuBmTY6GV8o0+4Yg
=5dBc
-----END PGP SIGNATURE-----

--=-5WbwE8FE7AMCkY8g4Lgx--



--===============2510094876654923452==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2510094876654923452==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung