Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: lcdproc
Date: Tue, 07 Jan 2003 21:17:37
Message-Id: 20030107210703.2C4835763@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200301-7
6 - - --------------------------------------------------------------------
7
8 PACKAGE : lcdproc
9 SUMMARY : remote code execution
10 DATE    : 2003-01-07 21:01 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 - From advisory:
16
17 "The vulnerabilities in LCDproc allow an attacker to remotely execute
18 arbitrary code or cause the LCDproc server to crash."
19
20 Read the full advisory at
21 http://online.securityfocus.com/archive/1/56411
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 app-misc/lcdproc-0.4.1-r1 or earlier update their systems as
27 follows:
28
29 emerge rsync
30 emerge lcdproc
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 - - --------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.1 (GNU/Linux)
38
39 iD8DBQE+G0HGfT7nyhUpoZMRAq7gAKCkO+SxDyRM7UQcNUrMLSntdEzt9ACfXRib
40 VNy+H91tV/pxs+oSU3udMAM=
41 =JLG/
42 -----END PGP SIGNATURE-----