Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: gzip (200306-05)
Date: Sat, 14 Jun 2003 16:43:45
Message-Id: 20030614164040.8911333775@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200306-05
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : gzip
9           SUMMARY : insecure temporary files
10              DATE : 2003-06-14 16:40 UTC
11           EXPLOIT : local
12 VERSIONS AFFECTED : <gzip-1.3.3-r2
13     FIXED VERSION : >=gzip-1.3.3-r2
14               CVE : CVE-1999-1332 CAN-2003-0367
15
16 - - - ---------------------------------------------------------------------
17
18 znew and gzexe in the gzip package allows local users to overwrite
19 arbitrary files via a symlink attack on temporary files.
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 sys-apps/gzip upgrade to gzip-1.3.3-r2 as follows
25
26 emerge sync
27 emerge gzip
28 emerge clean
29
30 - - - ---------------------------------------------------------------------
31 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
32 - - - ---------------------------------------------------------------------
33 -----BEGIN PGP SIGNATURE-----
34 Version: GnuPG v1.2.2 (GNU/Linux)
35
36 iD8DBQE+61AHfT7nyhUpoZMRAo0MAJ9OhzpYzwwQnGWVpjq+qNw4XS7wmwCfdLx9
37 TMRO/OEA1h7hpPUNRGXUPys=
38 =J+QB
39 -----END PGP SIGNATURE-----