Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: maelstrom (200305-11)
Date: Fri, 30 May 2003 19:35:39
Message-Id: 20030530130737.246483367D@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200305-11
6 - - - ---------------------------------------------------------------------
7
8 PACKAGE : maelstrom
9 SUMMARY : buffer overflow
10 DATE : 2003-05-30 13:07 UTC
11 EXPLOIT : local
12 VERSIONS AFFECTED : <maelstrom-3.0.6
13 FIXED VERSION : >=maelstrom-3.0.6
14 CVE : CAN-2003-0325
15
16 - - - ---------------------------------------------------------------------
17
18 A local buffer overflow exists in maelstrom.
19
20 Read the full advisory at
21 http://marc.theaimsgroup.com/?l=bugtraq&m=105337792703887&w=2
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 app-games/maelstrom upgrade to maelstrom-3.0.6 as follows
27
28 emerge sync
29 emerge maelstrom
30 emerge clean
31
32 - - - ---------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
34 - - - ---------------------------------------------------------------------
35 -----BEGIN PGP SIGNATURE-----
36 Version: GnuPG v1.2.2 (GNU/Linux)
37
38 iD8DBQE+11eYfT7nyhUpoZMRAk1QAKCPBtBxyjyCj+FJc9h/SG4pPfiEBQCdFGu4
39 k/ougSLhKUKE8cUqfbnniq4=
40 =5yhY
41 -----END PGP SIGNATURE-----