Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: mikmod (200307-01)
Date: Thu, 03 Jul 2003 08:37:55
Message-Id: 20030702212742.AD12E3376B@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200307-01
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : mikmod
9           SUMMARY : buffer overflow
10              DATE : 2003-07-02 21:27 UTC
11           EXPLOIT : local
12 VERSIONS AFFECTED : <mikmod-3.1.6a
13     FIXED VERSION : >=mikmod-3.1.6a
14               CVE : CAN-2003-0427
15
16 - - - ---------------------------------------------------------------------
17
18 quote from cve:
19 "Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to
20 execute arbitrary code via an archive file that contains a file with a
21 long filename."
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 media-sound/mikmod upgrade to mikmod-3.1.6a as follows
27
28 emerge sync
29 emerge mikmod
30 emerge clean
31
32 - - - ---------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
34 - - - ---------------------------------------------------------------------
35 -----BEGIN PGP SIGNATURE-----
36 Version: GnuPG v1.2.2 (GNU/Linux)
37
38 iD8DBQE/A05OfT7nyhUpoZMRAurSAJ9rTNLMgHoWghhGxpCC4wojbg1lRgCfTSYM
39 xh5/rPllaZxb4JLF77qNaWg=
40 =lFSW
41 -----END PGP SIGNATURE-----