[CLA-2001:434] Conectiva Linux Security Announcement - w3m

From: secure@conectiva.com.br
Date: 11/08/01


Date: Thu, 8 Nov 2001 16:53:10 -0200
Message-Id: <200111081853.QAA14768@frajuto.distro.conectiva>
To: conectiva-updates@papaleguas.conectiva.com.br, linuxlist@securityportal.com, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com
Subject: [CLA-2001:434] Conectiva Linux Security Announcement - w3m
From: secure@conectiva.com.br


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- --------------------------------------------------------------------------

PACKAGE : w3m
SUMMARY : w3m buffer overflow
DATE : 2001-11-08 16:52:00
ID : CLA-2001:434
RELEVANT
RELEASES : 5.0, 5.1, 6.0, 7.0

- -------------------------------------------------------------------------

DESCRIPTION
 w3m is a text based pager with WWW capability.
 
 Ogasawara Satoshi and Kobayashi Shigehiro discovered a
 vulnerability[1] in a MIME header parsing routine. A malicious web
 server administrator could execute arbitrary code in the client
 machine by sending malformed MIME headers inside the server HTTP
 responses.

SOLUTION
 All w3m users should upgrade.
 
 
 REFERENCES:
 1. http://www.securityfocus.com/bid/2895

DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/5.0/SRPMS/w3m-0.2.1-4U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/w3m-0.2.1-4U50_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.1/SRPMS/w3m-0.2.1-4U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/w3m-0.2.1-4U51_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/w3m-0.2.1-4U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/w3m-0.2.1-4U60_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/w3m-0.2.1-4U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/w3m-0.2.1-4U70_1cl.src.rpm

ADDITIONAL INSTRUCTIONS
 Users of Conectiva Linux version 6.0 or higher may use apt to perform
 upgrades of RPM packages:
 - add the following line to /etc/apt/sources.list if it is not there yet
   (you may also use linuxconf to do this):

 rpm [cncbr] ftp://atualizacoes.conectiva.com.br 6.0/conectiva updates

(replace 6.0 with the correct version number if you are not running CL6.0)

 - run: apt-get update
 - after that, execute: apt-get upgrade

 Detailed instructions reagarding the use of apt and upgrade examples
 can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en

- -------------------------------------------------------------------------
subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE76tSV42jd0JmAcZARAp+9AKCZPe5dVe4gG3EQs3wayCOZOXglwACfUNqc
P3J+nGO3e/zbYl/uBd3sqGY=
=Tw2Q
-----END PGP SIGNATURE-----



Relevant Pages

  • [CLA-2005:917] Conectiva Security Announcement - krb5
    ... It is recommended that all Kerberos users in Conectiva Linux upgrade ... UPDATED PACKAGES ... Detailed instructions regarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2004:889] Conectiva Security Announcement - sasl2
    ... It is recommended that all sasl2 users upgrade their packages. ... If you are using Conectiva Linux 9, ... Detailed instructions regarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2003:695] Conectiva Security Announcement - mpg123
    ... mpg123 is a command line mp3 player. ... All mpg123 users should upgrade. ... Detailed instructions reagarding the use of apt and upgrade examples ... Instructions on how to check the signatures of the RPM packages can be ...
    (Bugtraq)
  • [CLA-2003:675] Conectiva Security Announcement - ml85p
    ... related packages, including ml85p: ... this package is not distributed with Conectiva Linux; ... It is recommended that all ml85p and escputil users upgrade their ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2003:742] Conectiva Security Announcement - sendmail
    ... SUMMARY: Remote vulnerability ... Starting with Conectiva Linux 7.0, sendmail is no longer the default ... All sendmail users should upgrade immediately. ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)