| ★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-3137.html | Nouvelle recherche | Portail wanayoo |
![]() |
|
![]() |
|||
|
|
By |
|||||||||||||||||||||
| Package: | Vendor: |
| gnupg | SuSE, Red Hat, Conectiva |
| ispell | Red Hat |
| xinetd | Red Hat |
FREE Apache SSL Guide from ThawteCertification - Do you want to secure your Apache Web Server,but you're not sure how? Learn more with Thawte's FREE Guide. Get it todayat: http://www.gothawte.com/rd13.html
Linux Advisory Watch is a comprehensive newsletter that outlinesthe security vulnerabilities that have been announced throughout the week.It includes pointers to updated packages and descriptions of each vulnerability.
A format string vulnerability in versions of GnuPG before 1.0.6 hasbeen found. The error occurs when gpg encounters a filename suffix thatis not ".gpg" and prints the filename without the suffix as a default tothe terminal. The bug allows an attacker to execute arbitrary code as theuser calling gpg. Werner Koch, the author of the GnuPG package, statesthat when the "--batch" commandline option is used (such as when verifyingrpm packages, see Section 3 of this announcement, or when used in MUAs(Mail User Agent)), the error cannot occur since this option supressesthe printout of the filename on the terminal. There is no temporary workaroundfor the problem except for the "--batch" commandline option to gpg. Werecommend to update the gpg package on all systems where it is installed.
As an additional reason to update the package, it should be noted thatgnupg 1.0.5 (packages were available on our ftp server) fixed some security-relatedproblems, where one of them could allow an attacker with access to yourkey ring to compute the private key in considerably less time.
i386 Intel Platform:SuSE-7.1ispell
ftp://ftp.suse.com/pub/suse/i386/update/7.1/
sec1/gpg-1.0.6-0.i386.rpm
39153126feeddf43a939c89a9b1a33fd
SuSE Vendor Advisory:
http://www.linuxsecurity.com/advisories/suse_advisory-1418.html
i386: Red Hat
ftp://updates.redhat.com/7.1/en/os/i386/
gnupg-1.0.6-1.i386.rpm
06dea237f91666032224592e2af68894Red Hat Vendor Advisory:
http://www.linuxsecurity.com/advisories/redhat_advisory-1422.html
i386 Conectiva:
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/
gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/
gnupg-doc-1.0.6-1cl.i386.rpmConectiva Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1423.html
The ispell program uses mktemp() to open temporary files - this makesit vulnerable to symlink attacks. This version now uses mkstemp(), andalso switches from gets() to fgets() in two locations dealing with userinput. The patches for ispell are from OpenBSD.
i386:
ftp://updates.redhat.com/5.2/en/os/i386/
ispell-3.1.20-26.52.i386.rpmPLEASE SEE VENDOR ADVISORYFOR OTHER LANGUAGES
Red Hat Vendor Advisory:
http://www.linuxsecurity.com/advisories/redhat_advisory-1421.html
Xinetd runs with umask 0 - this means that applications using the xinetdumask and not setting the permissions themselves (like swat from the sambapackage), will create world writable files. This update sets the defaultumask to 022. Also, the web interface for linuxconf did not work in RedHat Linux 7.1. Other minor issues have also been addressed.
Red Hat Linux7.1:i386:
ftp://updates.redhat.com/7.1/en/os/i386/
xinetd-2.1.8.9pre15-2.i386.rpm
18d39a2f89bf09dc74b6cdc5286e0c49Red Hat Vendor Advisory:
http://www.linuxsecurity.com/advisories/redhat_advisory-1420.html
| Contact Us | Legal Notice | About Our Site © Guardian Digital, Inc., 2000 |