Gentoo Archives: gentoo-user-es

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-user-es] [gentoo-announce] GLSA: groff
Date: Sat, 19 Oct 2002 19:11:10
Message-Id: 20021019195320.E792B336EA@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200210-005
6 - - --------------------------------------------------------------------
7
8 PACKAGE : groff
9 SUMMARY : buffer overflow
10 DATE    : 2002-10-19 19:30 UTC
11
12 - - --------------------------------------------------------------------
13
14 The groff preprocessor contains an exploitable buffer overflow. If
15 groff can be invoked within the LPRng printing system, an attacker
16 can gain rights as the "lp" user.
17
18 Remote exploitation may be possible if lpd is running and is accessible
19 remotely, and the attacker knows the name of the printer and spoolfile.
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 sys-apps/groff-1.17.2-r2 and earlier update their systems
25 as follows:
26
27 emerge rsync
28 emerge groff
29 emerge clean
30
31 - - --------------------------------------------------------------------
32 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
33 - - --------------------------------------------------------------------
34 -----BEGIN PGP SIGNATURE-----
35 Version: GnuPG v1.2.0 (GNU/Linux)
36
37 iD8DBQE9sbgvfT7nyhUpoZMRAu3QAJkBRAmp4Dyz9TPJl2ADXkXZaq36VwCfdTbG
38 KxmxU5E0w0og6TWQgPiZx7M=
39 =mU/h
40 -----END PGP SIGNATURE-----
41 _______________________________________________
42 gentoo-announce mailing list
43 gentoo-announce@g.o
44 http://lists.gentoo.org/mailman/listinfo/gentoo-announce