Login
Newsletter
Werbung

Sicherheit: Überschreiben von Dateien in Suds
Aktuelle Meldungen Distributionen
Name: Überschreiben von Dateien in Suds
ID: USN-2008-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 12.10, Ubuntu 13.04
Datum: Do, 24. Oktober 2013, 23:21
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2217
Applikationen: Suds

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8973471916294459994==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="9H5MtjGx7LQMbqasx7ewR6vfk04mr8uHp"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--9H5MtjGx7LQMbqasx7ewR6vfk04mr8uHp
Content-Type: text/plain; charset=UTF-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2008-1
October 24, 2013

suds vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Suds could be made to overwrite files.

Software Description:
- suds: Lightweight SOAP client for Python

Details:

Ralph Loader discovered that Suds incorrectly handled temporary files. A
local attacker could possibly use this issue to overwrite arbitrary files.
In the default installation of Ubuntu, this should be prevented by the Yama
link restrictions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-suds 0.4.1-5ubuntu0.13.04.1

Ubuntu 12.10:
python-suds 0.4.1-5ubuntu0.12.10.1

Ubuntu 12.04 LTS:
python-suds 0.4.1-2ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2008-1
CVE-2013-2217

Package Information:
https://launchpad.net/ubuntu/+source/suds/0.4.1-5ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/suds/0.4.1-5ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/suds/0.4.1-2ubuntu1.1



--9H5MtjGx7LQMbqasx7ewR6vfk04mr8uHp
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSaWPPAAoJEGVp2FWnRL6TymQQAKylrPlPberaO0oXjbU0C2xj
VMiG0WeijeSxucQ5siYMyOLCrm23fd1SbuYDM8StrZOfr6rdIn5mroQ0BCRPBOww
pGt2dokokyPUc6GmOeZyzAQdP1ENPf2qq5y3vc3Nh2NwQmIg6r/2BLFuZ7N1DczJ
K2edPMs5RF/HWkv1QS4FbcNLGYypmX9JKElcvUakKP2ib4nXjfE3/7ZaeW7Dl6ie
4aXjggoBl4B1JjZbYSN/YpzPmrW6n+72zUVquUEQcLz2yve9VXt9YgoICzW1w7KX
hNUTAidHoqZbiJ9IFFqzq5p/8oWep4DSg3u00aAjk5Z1B+WhAt7HN4Or3siCgeqj
qhBdAAQRi0zLxoiDxLG4mTQVXTKPENPQ7VQvUwZcvdjcQJyL7F5n+W1vCBOqrh6p
8Z0IglV3dg++Q1KjJ7U5I8Vkr6IIDRH5bkQSrHwUKysI1h/SF2Osf3lRrWCAFPnR
8qov0ndNJnKWz3Or97h5/8EiZfBv6cBjJFUHay20JMAK/4+hJ0JPp0f+juqzVBnI
iDmzeObRt5p76irvz4e+GIzYv9OfC0cnGWscAzRaWe5N3IbFPa2sRyq4YvkKAUxc
ofu/uB6OOcU9qk6mDNPzs94l7T0mhK++BBpVVZO1bBfYZw546ir00G6Wg9xI6txg
Q6Q2OYvWTvTUiNHK6vOf
=caf5
-----END PGP SIGNATURE-----

--9H5MtjGx7LQMbqasx7ewR6vfk04mr8uHp--


--===============8973471916294459994==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8973471916294459994==--
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung