View previous topic :: View next topic |
Author |
Message |
Klavs Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/5492292243e8b08c7ba8ef.jpg)
Joined: 22 May 2002 Posts: 536 Location: Denmark
|
Posted: Wed Mar 05, 2003 12:45 pm Post subject: sys-apps/file vulnerability !! |
|
|
Hi guys,
see this: http://www.securityfocus.org/archive/1/313837/2003-03-02/2003-03-08/0
I can see on file's homepage that the newest version is v3.41 - and as this vulnerability only goes for v3.39 and older - I'm suggesting we get an updated ebuild out ![Smile :)](images/smiles/icon_smile.gif) _________________ Best regards,
Klavs Klavsen
Denmark
Working with Unix is like wrestling a worthy opponent.
Working with windows is like attacking a small whining child
who is carrying a .38. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Klavs Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/5492292243e8b08c7ba8ef.jpg)
Joined: 22 May 2002 Posts: 536 Location: Denmark
|
Posted: Wed Mar 05, 2003 1:51 pm Post subject: |
|
|
Oh, and ofcourse why this is a bad thing is that
It is NOT only a local exploit - it can be EXPLOITED REMOTELY if you use content-filters such as amavis, amavis-ng amavisd or amavisd-new as far as I'm aware of.
So all you using those filters - and perhaps others? would do nicely to upgrade your file tool ![Smile :)](images/smiles/icon_smile.gif) _________________ Best regards,
Klavs Klavsen
Denmark
Working with Unix is like wrestling a worthy opponent.
Working with windows is like attacking a small whining child
who is carrying a .38. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pjp Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
![](images/avatars/1154772887439692d88303b.jpg)
Joined: 16 Apr 2002 Posts: 20588
|
Posted: Wed Mar 05, 2003 2:20 pm Post subject: |
|
|
Doesn't look like there's a bug report yet, but the devs probably know about it. _________________ Quis separabit? Quo animo? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|