Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: noweb (200306-16)
Date: Sat, 28 Jun 2003 20:35:42
Message-Id: 20030628202329.7CB3D33747@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200306-16
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : noweb
9           SUMMARY : insecure temporary file creations
10              DATE : 2003-06-28 20:23 UTC
11           EXPLOIT : local
12 VERSIONS AFFECTED : <noweb-2.9-r3
13     FIXED VERSION : >=noweb-2.9-r3
14               CVE : CAN-2003-0381
15
16 - - - ---------------------------------------------------------------------
17
18 quote from cve:
19 "Multiple vulnerabilities in noweb 2.9 and earlier creates temporary
20 files insecurely, which allows local users to overwrite arbitrary files
21 via multiple vectors including the noroff script."
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 app-text/noweb upgrade to noweb-2.9-r3 as follows
27
28 emerge sync
29 emerge noweb
30 emerge clean
31
32 - - - ---------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
34 - - - ---------------------------------------------------------------------
35 -----BEGIN PGP SIGNATURE-----
36 Version: GnuPG v1.2.2 (GNU/Linux)
37
38 iD8DBQE+/flBfT7nyhUpoZMRAsBhAJ9J9rMW/ecxem29uUOs6v3ARwVvpQCeKOjN
39 rh2kN/TzLR17eFLuzDsPHjc=
40 =ZAMM
41 -----END PGP SIGNATURE-----