Login
Newsletter
Werbung

Sicherheit: Unsichere Verwendung von temporären Dateien in lprng
Aktuelle Meldungen Distributionen
Name: Unsichere Verwendung von temporären Dateien in lprng
ID: 200306-04
Distribution: Gentoo
Plattformen: Keine Angabe
Datum: So, 15. Juni 2003, 13:00
Referenzen: Keine Angabe
Applikationen: LPRng

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

--------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-04
--------------------------------------------------------------------

          PACKAGE : lprng
          SUMMARY : symbolic link attack
             DATE : 2003-06-14 16:40 UTC
          EXPLOIT : local
VERSIONS AFFECTED : <lprng-3.8.12-r1
    FIXED VERSION : >=lprng-3.8.12-r1
              CVE : CAN-2003-0136

--------------------------------------------------------------------

psbanner in the LPRng package allows local users to overwrite arbitrary
files via a symbolic link attack on the /tmp/before file.

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-print/lprng upgrade to lprng-3.8.12-r1 as follows

emerge sync
emerge lprng
emerge clean

--------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
--------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE+60/yfT7nyhUpoZMRApsGAJ4n+2mfrL/F9DAL9eg0ggh+XGOS+ACeLp24
B/u/+deWB5K8uX3PhtA8HqI=
=T6zX
-----END PGP SIGNATURE-----
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung