Gentoo Archives: gentoo-user-es

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-user-es] [gentoo-announce] GLSA: sharutils
Date: Wed, 30 Oct 2002 08:10:08
Message-Id: 20021030140919.CA23B3368F@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200210-012
6 - - --------------------------------------------------------------------
7
8 PACKAGE : sharutils
9 SUMMARY : inadequate checks on user-specified output files
10 DATE    : 2002-10-30 14:10 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 The uudecode utility would create an output file without checking
16 to see if it was about to write to a symlink or a pipe. If a
17 user uses uudecode to extract data into open shared directories,
18 such as /tmp, this vulnerability could be used by a local attacker
19 to overwrite files or lead to privilege escalation.
20
21 Read the full advisory at
22 http://www.kb.cert.org/vuls/id/336083
23
24 SOLUTION
25
26 It is recommended that all Gentoo Linux users who are running
27 sys-apps/sharutils-4.2.1-r5 and earlier update their systems as follows:
28
29 emerge rsync
30 emerge sharutils
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 - - --------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.0.7 (GNU/Linux)
38
39 iD8DBQE9v+gPfT7nyhUpoZMRAvONAKCEtURIf7x9ywYgn5bk3bXGRgtFYwCgulgp
40 pN2sMd4yQUooVdzqeu4OmNY=
41 =DcXc
42 -----END PGP SIGNATURE-----
43 _______________________________________________
44 gentoo-announce mailing list
45 gentoo-announce@g.o
46 http://lists.gentoo.org/mailman/listinfo/gentoo-announce