Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in TinTin++
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in TinTin++
ID: 201111-07
Distribution: Gentoo
Plattformen: Keine Angabe
Datum: So, 20. November 2011, 23:07
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0671
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0672
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0673
Applikationen: TinTin++

Originalnachricht

--nextPart4516725.b3JfILiDUK
Content-Type: Text/Plain;
charset="us-ascii
Content-Transfer-Encoding: quoted-printable

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201111-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: TinTin++: Multiple vulnerabilities
Date: November 20, 2011
Bugs: #209903
ID: 201111-07

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been reported in TinTin++ which could
allow a remote attacker to conduct several attacks, including the
execution of arbitrary code and Denial of Service.

Background
==========

TinTin++ is a free MUD gaming client.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 games-mud/tintin < 1.98.0 >= 1.98.0

Description
===========

Multiple vulnerabilities have been discovered in TinTin++. Please
review the CVE identifiers referenced below for details.

Impact
======

Remote unauthenticated attackers may be able to execute arbitrary code
with the privileges of the TinTin++ process, cause a Denial of Service,
or truncate arbitrary files in the top level of the home directory
belonging to the user running the TinTin++ process.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All TinTin++ users should upgrade to the latest stable version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=games-mud/tintin-1.98.0"

NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since March 25, 2008. It is likely that your system is
already no longer affected by this issue.

References
==========

[ 1 ] CVE-2008-0671
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0671
[ 2 ] CVE-2008-0672
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0672
[ 3 ] CVE-2008-0673
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0673

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201111-07.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2011 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

--nextPart4516725.b3JfILiDUK
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.18 (GNU/Linux)

iQIcBAABCAAGBQJOyUNEAAoJEDa6ZWES7jAAlGkP/1apc+AehlHqfSuKAErPDi4Z
F5DpCiBj2NbOLa3LUbEWWkGhNpxEdrfsD9oueniL4WoYLn+FdvPttij9ZMpTMGjo
NeBZ3xj8HkUdeRF5XokSL3j8ZQ5yvVOQKDv9ywUmDmYhB+DBBmfoFTOaN1pmItEU
SNtmruXLctLvkybB7qR3reX9is2TkOpAoso+YeHit9m50n5g9NmwMGkznD92DBcn
8NTxF0jorAqeNOxhVSY6eoUzJZRntraJi5yxakz8P56oCjItN9i7UTz/aMRtjpbq
kVFQJfZkCRVD/HsR7V6QLZZbeWKNNzMVzFROTJZTA6fuagvLAILU+hZUWmR5/PM2
0FYzlaUjHWB/b2lyIxztLLPlh2x0o1TdAJiv/HFvssN0qS/IghDeD/ziDp2/OaIR
swIHTxti++0/tFwqk+OaHmfzdQZx8VUmMRjK/fIXT2rBLhvffBx/v1c8oRBqMVr8
DJIT2+g+8/bxMp8CDEJQPgqVimvRYjdGAjUmUgCEG2eifaC5QCcNvd58Ow+dkMzo
5/CpxQfk/HHWJFKgUs6P6ZxuVGN7G5grlUsmN82B4LCTChJupgKc3sftTi7pv5pz
XwyKzxzLm4yvZ3GSQIbFM+LATBltUDjLT10jEd7eqbfe9hvuwL3GIbfLFjy6ckt9
SPmBRE+2e+BdVhJsbGGV
=m/Hc
-----END PGP SIGNATURE-----

--nextPart4516725.b3JfILiDUK--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung