Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: GLSA: eroaster (200309-04)

GLSA: eroaster (200309-04)

From: Daniel Ahlberg <aliz_at_gentoo.org>
Date: Tue, 2 Sep 2003 11:57:49 +0200 (CEST)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-04
- - - ---------------------------------------------------------------------

          PACKAGE : eroaster
          SUMMARY : symlink attack
             DATE : 2003-09-02 09:57 UTC
          EXPLOIT : local
VERSIONS AFFECTED : <eroaster-2.1.0-r2
    FIXED VERSION : >=eroaster-2.1.0-r2
              CVE : CAN-2003-0656

- - - ---------------------------------------------------------------------

Previous eroaster versions allowwed local users to overwrite arbitrary
files via a symlink attack on a temporary file that is used as a lockfile.

SOLUTION

It is recommended that all Gentoo Linux users who are running
app-cdr/eroaster upgrade to eroaster-2.1.0-r2 as follows:

emerge sync
emerge eroaster
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz
- - - ---------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/VGmdfT7nyhUpoZMRAg2YAKCY0hNYsrhirHwqHpN9exykGJhn3wCfbyIW
gYYFsd1A4rF6FOni7qg3jdg=
=rrmf
-----END PGP SIGNATURE-----
Received on Sep 02 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]