Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] GLSA: pam_ldap
Date: Wed, 30 Oct 2002 16:33:46
Message-Id: 20021030223341.208233368F@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200210-013
6 - - --------------------------------------------------------------------
7
8 PACKAGE : pam_ldap
9 SUMMARY : format string attack
10 DATE    : 2002-10-30 22:10 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 Versions 143 and earlier of the pam_ldap module are vulnerable to a
16 format string attack. A local attacker could supply a malicious
17 format string when opening a configuration file, which could allow
18 the attacker to execute arbitrary code on the system with elevated
19 privileges.
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 net-libs/pam_ldap-134-r1 and earlier update their systems as follows:
25
26 emerge rsync
27 emerge pam_ldap
28 emerge clean
29
30 - - --------------------------------------------------------------------
31 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
32 - - --------------------------------------------------------------------
33 -----BEGIN PGP SIGNATURE-----
34 Version: GnuPG v1.0.7 (GNU/Linux)
35
36 iD8DBQE9wF5EfT7nyhUpoZMRArjCAJsEkwr+rMxtCSwJ4ylCHo126BBlZwCfRE2Y
37 /snm/fWy0G8/l4C+85kHfgc=
38 =O57d
39 -----END PGP SIGNATURE-----