Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: slocate
Date: Sun, 02 Feb 2003 13:43:55
Message-Id: 20030202133512.A5EFE33B4D@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200302-02
6 - - --------------------------------------------------------------------
7
8 PACKAGE : slocate
9 SUMMARY : buffer overflow
10 DATE : 2003-02-02 13:36 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 - From advisory:
16
17 "The overflow appears when the slocate is runned with two parameters:
18 - -c and -r, using as arguments a 1024 (or 10240, as Knight420 has
19 informed us earlier) bytes string."
20
21 Read the full advisory at
22 http://www.usg.org.uk/advisories/2003.001.txt
23
24 SOLUTION
25
26 It is recommended that all Gentoo Linux users who are running
27 sys-apps/slocate upgrade to slocate-2.7 as follows:
28
29 emerge sync
30 emerge -u slocate
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 - - --------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.1 (GNU/Linux)
38
39 iD8DBQE+PR7NfT7nyhUpoZMRApEYAJ4uD5qRerI0di1uC0UOIrmMsFaIngCgk2JI
40 XW5zgRH8d560fe7weHDCPrw=
41 =H1YI
42 -----END PGP SIGNATURE-----