Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o
Subject: GLSA: gnupg (200307-06)
Date: Sat, 19 Jul 2003 12:47:27
Message-Id: 20030719142754.925F79FD0E@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200307-06
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : gnupg
9           SUMMARY : gpg setgid
10              DATE : 2003-07-19 14:27 UTC
11           EXPLOIT : local
12 VERSIONS AFFECTED : <gnupg-1.2.2-r1
13     FIXED VERSION : >=gnupg-1.2.2-r1
14               CVE :
15
16 - - - ---------------------------------------------------------------------
17
18 gpg needs to be setuid to make use of protected memory space, however the
19 setgid bit allowed gpg user to overwrite goup root writable files and is
20 therefor unnecessary.
21
22 SOLUTION
23
24 It is recommended that all Gentoo Linux users who are running
25 app-crypt/gnupg upgrade to gnupg-1.2.2-r1 as follows
26
27 emerge sync
28 emerge gnupg
29 emerge clean
30
31 - - - ---------------------------------------------------------------------
32 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
33 taviso@g.o
34 - - - ---------------------------------------------------------------------
35 -----BEGIN PGP SIGNATURE-----
36 Version: GnuPG v1.2.2 (GNU/Linux)
37
38 iD8DBQE/GVVqfT7nyhUpoZMRAuvoAJ4+sGRjZzE9N6CvSsZ/igqlEYOmrgCghtXb
39 mjW0tn0aoFEPuaOOVMv0cMk=
40 =09VQ
41 -----END PGP SIGNATURE-----