Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: kopete (200305-03)
Date: Wed, 14 May 2003 08:17:01
Message-Id: 20030514073951.5F11F33740@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200305-03
6 - - - ---------------------------------------------------------------------
7
8 PACKAGE : kopete
9 SUMMARY : Unsafe command line cleansing
10 DATE : 2003-05-14 07:39 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <kopete-0.6.2
13 FIXED VERSION : >=kopete-0.6.2
14 CVE : CAN-2003-0256
15
16 - - - ---------------------------------------------------------------------
17
18 The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the
19 command line when executing gpg, which allows remote attackers to
20 execute arbitrary commands.
21
22 SOLUTION
23
24 It is recommended that all Gentoo Linux users who are running
25 net-im/kopete upgrade to kopete-0.6.2 as follows:
26
27 emerge sync
28 emerge kopete
29 emerge clean
30
31 - - - ---------------------------------------------------------------------
32 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
33 - - - ---------------------------------------------------------------------
34 -----BEGIN PGP SIGNATURE-----
35 Version: GnuPG v1.2.2 (GNU/Linux)
36
37 iD8DBQE+wfLGfT7nyhUpoZMRAoKwAJ99Gdwhcy436LanEEvAmWh/lgdvaQCgv8yw
38 uo9SkNlFO2fkO41LozwZTPs=
39 =r/Ih
40 -----END PGP SIGNATURE-----