klieber Bodhisattva
Joined: 17 Apr 2002 Posts: 3657 Location: San Francisco, CA
|
Posted: Wed Oct 30, 2002 2:44 pm Post subject: [gentoo-announce] GLSA: sharutils |
|
|
Daniel Ahlberg wrote: | - - -------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200210-012
- - --------------------------------------------------------------------
PACKAGE : sharutils
SUMMARY: inadequate checks on user-specified output files
DATE : 2002-10-30 14:10 UTC
EXPLOIT : local
- - --------------------------------------------------------------------
The uudecode utility would create an output file without checking to see if it was about to write to a symlink or a pipe. If a user uses uudecode to extract data into open shared directories, such as /tmp, this vulnerability could be used by a local attacker to overwrite files or lead to privilege escalation.
Read the full advisory at
http://www.kb.cert.org/vuls/id/336083
SOLUTION
It is recommended that all Gentoo Linux users who are running sys-apps/sharutils-4.2.1-r5 and earlier update their systems as follows:
emerge rsync
emerge sharutils
emerge clean
- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - -------------------------------------------------------------------- |
Mailing List Archive: http://lists.gentoo.org/pipermail/gentoo-announce/2002-October/000231.html
--kurt _________________ The problem with political jokes is that they get elected |
|