drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in coreutils
Name: |
Zwei Probleme in coreutils |
|
ID: |
USN-2473-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, Ubuntu 14.04 LTS |
|
Datum: |
Do, 15. Januar 2015, 08:09 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4135
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9471 |
|
Applikationen: |
GNU Coreutils |
|
Originalnachricht |
--===============2064384113084287735== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="envbJBWh7q8WU6mo" Content-Disposition: inline
--envbJBWh7q8WU6mo Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-2473-1 January 14, 2015
coreutils vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS
Summary:
date and touch could be made to crash or run programs if they handled specially crafted input.
Software Description: - coreutils: GNU core utilities
Details:
It was discovered that the distcheck rule in dist-check.mk in GNU coreutils allows local users to gain privileges via a symlink attack on a directory tree under /tmp. This issue only affected Ubuntu 10.04 LTS. (CVE-2009-4135)
Bertrand Jacquin and Fiedler Roman discovered date and touch incorrectly handled user-supplied input. An attacker could possibly use this to cause a denial of service or potentially execute code. (CVE-2014-9471)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04 LTS: coreutils 8.21-1ubuntu5.1
Ubuntu 12.04 LTS: coreutils 8.13-3ubuntu3.3
Ubuntu 10.04 LTS: coreutils 7.4-2ubuntu3.1
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-2473-1 CVE-2009-4135, CVE-2014-9471
Package Information: https://launchpad.net/ubuntu/+source/coreutils/8.21-1ubuntu5.1 https://launchpad.net/ubuntu/+source/coreutils/8.13-3ubuntu3.3 https://launchpad.net/ubuntu/+source/coreutils/7.4-2ubuntu3.1
--envbJBWh7q8WU6mo Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQEcBAEBAgAGBQJUtwScAAoJEPMhclmdjS6XAXwH/AiSss8qAizo4hlfo6fjV+2F YcGeLTWr/47fC590oJaoKor1xhCSiLCW5usJOhYVTUDfKUKjMoQqxDTIKiiiNRGR dXsylOR4En/QpxwDWkTvuyIkIpAABui1mO3loTzD8oiaxwCmWAI4QubGUYdapAMP ju2k5l8M9lt9aGrgBOgGNuFg8WCx54M7PO2N6I3Gq18u8DQEB8aEEdowJmMXKDJF TW3LM96F4rEk5E9XmnIkhN2x9xpbM5YcfXcKAtQy4/hHGG0GE7cx/Y3QXXVXS7R3 ZrcuAgywZFsNMH4d4qgHwRni2SG/W7ko1WKifLL6a28npuxwCjmdS4tiqXc1UQk= =OY1k -----END PGP SIGNATURE-----
--envbJBWh7q8WU6mo--
--===============2064384113084287735== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============2064384113084287735==--
|
|
|
|