Login
Newsletter
Werbung

Sicherheit: Unsichere Verwendung von /tmp in mgetty (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Unsichere Verwendung von /tmp in mgetty (Aktualisierung)
ID: DSA-011-2
Distribution: Debian
Plattformen: Debian potato
Datum: Di, 6. März 2001, 12:00
Referenzen: Keine Angabe
Applikationen: mgetty
Update von: Unsichere Verwendung von /tmp in mgetty

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

----------------------------------------------------------------------------
Debian Security Advisory DSA-011-2 security@debian.org
http://www.debian.org/security/ Martin Schulze
March 6, 2001
----------------------------------------------------------------------------

Package : mgetty
Vulnerability : insecure tempfile creation
Debian-specific: no

In Debian Security Advisory DSA 011-1 we have reported insecure
creation of temporary files in the mgetty package that have been
fixed. For details please read the main advisory.

The most recent advisory covering proftpd missed two architectures that
were released with Debian GNU/Linux 2.2. Therefore this advisory is
only an addition to DSA 011-1 and only adds the relevant package for
the Motorola 680x0 and PowerPC architecture.

We recommend you upgrade your sudo packages for m68k immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 2.2 alias potato
------------------------------------

Potato was released for the alpha, arm, i386, m68k, powerpc and sparc
architectures.


Motorola 680x0 architecture:

mgetty-fax_1.1.21-3potato1_m68k.deb
MD5 checksum: c175cdd07927e5a6e9f6ebecbd91366b
mgetty-viewfax_1.1.21-3potato1_m68k.deb
MD5 checksum: 8aa48ed8b00d7873452cac3970c47877
mgetty-voice_1.1.21-3potato1_m68k.deb
MD5 checksum: 89a9c11cfaa04cac4f2cc752714e1f3f
mgetty_1.1.21-3potato1_m68k.deb
MD5 checksum: 40b004e0dcaad89253a552e823809f7a

PowerPC architecture:

mgetty_1.1.21-3potato1_powerpc.deb
MD5 checksum: fe951cbfbbd37d26cd7c210ee9eee8a1
mgetty-fax_1.1.21-3potato1_powerpc.deb
MD5 checksum: e9b3c8b63f82333cc8cb22eeecaaa1c9
mgetty-viewfax_1.1.21-3potato1_powerpc.deb
MD5 checksum: afbed28e1382f53cfdca42c089d56516
mgetty-voice_1.1.21-3potato1_powerpc.deb
MD5 checksum: 244d5c6525382b342117ec2e72ee0f1c


These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/ soon.

For not yet released architectures please refer to the appropriate
directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .

----------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-securitydists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE6pEaUW5ql+IAeqTIRAmP6AJ9v+Bq/HsY25wy2lKIsMqYZk7kzYACfYsdI
s8xTuLHFx8t4cPUGG1d0a6c=
=cJZr
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact
listmaster@lists.debian.org
Pro-Linux
Pro-Linux @Twitter
Neue Nachrichten
Werbung