Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-security@g.o, gentoo-announce@g.o
Subject: [gentoo-announce] GLSA: scrollkeeper
Date: Wed, 04 Sep 2002 05:38:55
Message-Id: 200209041238.53201.aliz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT
6 - - --------------------------------------------------------------------
7
8 PACKAGE :scrollkeeper
9 SUMMARY :insecure temporary file creation
10 DATE :2002-09-04 10:30 UTC
11
12 - - --------------------------------------------------------------------
13
14 OVERVIEW
15
16 The scrollkeeper-get-cl program
17 creates temporary files in an insecure manner in /tmp using guessable
18 filenames.
19
20 DETAIL
21
22 The scrollkeeper-get-cl program creates temporary files in an insecure
23 manner in /tmp using guessable filenames.
24 Since scrollkeeper is called automatically when a user logs into a Gnome
25 session, an attacker with local access can easily create and overwrite
26 files as another user.
27
28 More information can be found at:
29
30 http://online.securityfocus.com/archive/1/290090/2002-09-01/2002-09-07/0
31 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0662
32
33 SOLUTION
34
35 It is recommended that all Gentoo Linux users who are running
36 app-text/scrollkeeper-0.3.11 and earlier update their systems
37 as follows:
38
39 emerge rsync
40 emerge scrollkeeper
41 emerge clean
42
43 - - --------------------------------------------------------------------
44 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
45 - - --------------------------------------------------------------------
46 -----BEGIN PGP SIGNATURE-----
47 Version: GnuPG v1.0.7 (GNU/Linux)
48
49 iD8DBQE9deK8fT7nyhUpoZMRAm29AJ416vm6E/TpjOB+e4nqLcyqyPFEowCfRgq8
50 zc0ji+VXWKtdw8YQxHnTOXM=
51 =jomO
52 -----END PGP SIGNATURE-----