drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Unsichere Verwendung temporärer Dateien in eroaster
Name: |
Unsichere Verwendung temporärer Dateien in eroaster
|
|
ID: |
200309-04 |
|
Distribution: |
Gentoo |
|
Plattformen: |
Keine Angabe |
|
Datum: |
Di, 2. September 2003, 13:00 |
|
Referenzen: |
Keine Angabe |
|
Applikationen: |
ECLiPt Roaster |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
-------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-04 --------------------------------------------------------------------
PACKAGE : eroaster SUMMARY : symlink attack DATE : 2003-09-02 09:57 UTC EXPLOIT : local VERSIONS AFFECTED : <eroaster-2.1.0-r2 FIXED VERSION : >=eroaster-2.1.0-r2 CVE : CAN-2003-0656
--------------------------------------------------------------------
Previous eroaster versions allowwed local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.
SOLUTION
It is recommended that all Gentoo Linux users who are running app-cdr/eroaster upgrade to eroaster-2.1.0-r2 as follows:
emerge sync emerge eroaster emerge clean
-------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz -------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux)
iD8DBQE/VGmdfT7nyhUpoZMRAg2YAKCY0hNYsrhirHwqHpN9exykGJhn3wCfbyIW gYYFsd1A4rF6FOni7qg3jdg= =rrmf -----END PGP SIGNATURE-----
|
|
|
|