Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o, full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200711-01 ] gFTP: Multiple vulnerabilities
Date: Thu, 01 Nov 2007 23:09:04
Message-Id: 472A680B.8020207@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200711-01
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: gFTP: Multiple vulnerabilities
12 Date: November 01, 2007
13 Bugs: #188252
14 ID: 200711-01
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Two buffer overflow vulnerabilities have been discovered in fsplib code
22 used in gFTP.
23
24 Background
25 ==========
26
27 gFTP is an FTP client for the GNOME desktop environment.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 net-ftp/gftp < 2.0.18-r6 >= 2.0.18-r6
36
37 Description
38 ===========
39
40 Kalle Olavi Niemitalo discovered two boundary errors in fsplib code
41 included in gFTP when processing overly long directory or file names.
42
43 Impact
44 ======
45
46 A remote attacker could trigger these vulnerabilities by enticing a
47 user to download a file with a specially crafted directory or file
48 name, possibly resulting in the execution of arbitrary code
49 (CVE-2007-3962) or a Denial of Service (CVE-2007-3961).
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All gFTP users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=net-ftp/gftp-2.0.18-r6"
63
64 References
65 ==========
66
67 [ 1 ] CVE-2007-3961
68 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3961
69 [ 2 ] CVE-2007-3962
70 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3962
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 http://security.gentoo.org/glsa/glsa-200711-01.xml
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 http://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2007 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.5
99 -----BEGIN PGP SIGNATURE-----
100 Version: GnuPG v1.4.7 (GNU/Linux)
101 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
102
103 iD8DBQFHKmgLuhJ+ozIKI5gRAkHDAJ0bKesCCZXTosLIHdxRbEMF0qG1kgCeN+cX
104 +YXc0ftTGX5B5cD1DrdrrtU=
105 =n1oZ
106 -----END PGP SIGNATURE-----
107 --
108 gentoo-announce@g.o mailing list