|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: [CLA-2000:359] Conectiva Linux Security Announcement - ed
From: secure
CONECTIVA.COM.BRDate: Wed Dec 13 2000 - 14:28:25 CST
- Next message: bugzilla
REDHAT.COM: "[RHSA-2000:126-03] New BitchX packages are available"
- Previous message: BAILLEUX Christophe: "Potential Buffer Overflow vulnerability in bftpd-1.0.13"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -----------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE : ed
SUMMARY : Insecure temporary file handling
DATE : 2000-12-13 18:27:00
ID : CLA-2000:359
RELEVANT
RELEASES : 4.0, 4.0es, 4.1, 4.2, 5.0, 5.1, 6.0
- ----------------------------------------------------------------------
DESCRIPTION
The "ed" editor creates temporary files in an insecure way, making it
vulnerable to symlink attacks.
SOLUTION
All users of the "ed" program should upgrade.
DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/4.0/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/pam-0.72-23cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/pam-0.72-23cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/pam-0.72-23cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/pam-0.72-23cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/pam-0.72-23cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/pam-0.72-23cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/pam-0.72-23cl.src.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/pam-0.72-23cl.i386.rpm
ADDITIONAL INSTRUCTIONS
Users of Conectiva Linux version 6.0 or higher may use apt to perform
upgrades:
- add the following line to /etc/apt/sources.list if it is not there yet
(you may also use linuxconf to do this):
rpm [cncbr] ftp://atualizacoes.conectiva.com.br 6.0/conectiva updates
- run: apt-get update
- after that, execute: apt-get upgrade
Detailed instructions reagarding the use of apt and upgrade examples
can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en
- ----------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key can be
obtained at http://www.conectiva.com.br/contato
- -----------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://www.conectiva.com.br/suporte/atualizacoes
- ----------------------------------------------------------------------
subscribe: atualizacoes-anuncio-subscribe
papaleguas.conectiva.com.br
unsubscribe: atualizacoes-anuncio-unsubscribe
papaleguas.conectiva.com.br
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE6N9vo42jd0JmAcZARAvhqAKDFVRi+UQ7pkDSANzL3JnQlq0RWIQCgoiCn
gZhIOgDeQQwWeoSQBATA28Y=
=Nnd8
-----END PGP SIGNATURE-----
- Next message: bugzilla
REDHAT.COM: "[RHSA-2000:126-03] New BitchX packages are available"
- Previous message: BAILLEUX Christophe: "Potential Buffer Overflow vulnerability in bftpd-1.0.13"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]