Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: bladeenc
Date: Wed, 05 Feb 2003 16:33:51
Message-Id: 20030205125027.1D9675761@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200302-04
6 - - --------------------------------------------------------------------
7
8 PACKAGE : bladeenc
9 SUMMARY : arbitrary code execution
10 DATE : 2003-02-05 12:55 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 - From advisory:
16
17 "A wave file let the attacker to execute all the code he want on the
18 victim"
19
20 Read the full advisory at:
21 http://www.pivx.com/luigi/adv/blade942-adv.txt
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 media-sound/bladeenc upgrade to bladeenc-0.94.2-r1 as follows:
27
28 emerge sync
29 emerge -u bladeenc
30 emerge clean
31
32 - - --------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
34 styx@g.o
35 - - --------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.1 (GNU/Linux)
38
39 iD8DBQE+QQnMfT7nyhUpoZMRAj4gAKCysKGdI94DM7FfPu24xfxjhPPNSgCgowXK
40 b+MxfjWXGIiJs2VVyA848RM=
41 =Z9lw
42 -----END PGP SIGNATURE-----