Login
Newsletter
Werbung

Sicherheit: Ungewolltes Ausführen von Programmen in lv
Aktuelle Meldungen Distributionen
Name: Ungewolltes Ausführen von Programmen in lv
ID: 200305-07
Distribution: Gentoo
Plattformen: Keine Angabe
Datum: Di, 20. Mai 2003, 13:00
Referenzen: Keine Angabe
Applikationen: lv

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

--------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200305-07
--------------------------------------------------------------------

PACKAGE : lv
SUMMARY : arbitrary command execution
DATE : 2003-05-19 07:10 UTC
EXPLOIT : local
VERSIONS AFFECTED : <lv-4.49.5
FIXED VERSION : >=lv-4.49.5
CVE : CAN-2003-0188

--------------------------------------------------------------------

Previous versions of lv read the file .lv in the current directory.
Becuse this file could be created by other users and could contain
malicious commands to execute upon viewing certain files this is
considered a potential local root exploit.

SOLUTION

It is recommended that all Gentoo Linux users who are running
app-text/lv upgrade to lv-4.49.5 as follows

emerge sync
emerge lv
emerge clean

--------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
nakano@gentoo.org
--------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE+yINxfT7nyhUpoZMRAvqqAJ9bt/LnN/GExeGVsye65ts1zN+lWgCdEvhA
CpJZVas9U0bmZ6iG0hQ5/9k=
=jRrn
-----END PGP SIGNATURE-----
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung