[CLA-2002:460] Conectiva Linux Security Announcement - pine

From: secure@conectiva.com.br
Date: 01/31/02


Date: Thu, 31 Jan 2002 12:04:16 -0200
To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com
From: secure@conectiva.com.br


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- --------------------------------------------------------------------------

PACKAGE : pine
SUMMARY : URL handler vulnerability
DATE : 2002-01-31 12:01:00
ID : CLA-2002:460
RELEVANT
RELEASES : 5.0, prg graficos, ecommerce, 5.1, 7.0

- -------------------------------------------------------------------------

DESCRIPTION
 Pine is a mail and news text based client developed by the Washington
 University[1].
 
 A vulnerability[2] in the pine URL handler was discovered that allows
 remote attackers to execute arbitrary shell commands in the user's
 machine by encapsulating them in a URL using environment variables.
 
 This vulnerability only affects users whith the msg-view-url option
 enabled (which is not the default).
 
 It was originally discovered[3] by Jim Hebert <jhebert@jhebert.cx> on
 November 18, 1999, rediscovered by zen-parse <zen-parse@gmx.net> on
 October 20, 2001 and reannounced to Bugtraq on January 5, 2002.

SOLUTION
 All pine users should upgrade.
 
 REFERENCES:
 1.http://www.washington.edu/pine/
 2.http://www.securityfocus.com/bid/3815
 3.http://www.securityfocus.com/archive/1/35296

DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/5.0/SRPMS/pine-4.44L-1U50_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/pine-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/pico-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/pilot-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/SRPMS/pine-4.44L-1U51_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/pine-4.44L-1U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/pilot-4.44L-1U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/pico-4.44L-1U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/pine-4.44L-1U70_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/pico-4.44L-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/pine-4.44L-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/pilot-4.44L-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/SRPMS/pine-4.44L-1U50_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/pine-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/pico-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/pilot-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/SRPMS/pine-4.44L-1U50_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/pine-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/pico-4.44L-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/pilot-4.44L-1U50_1cl.i386.rpm

ADDITIONAL INSTRUCTIONS
 Users of Conectiva Linux version 6.0 or higher may use apt to perform
 upgrades of RPM packages:
 - add the following line to /etc/apt/sources.list if it is not there yet
   (you may also use linuxconf to do this):

 rpm [cncbr] ftp://atualizacoes.conectiva.com.br 6.0/conectiva updates

(replace 6.0 with the correct version number if you are not running CL6.0)

 - run: apt-get update
 - after that, execute: apt-get upgrade

 Detailed instructions reagarding the use of apt and upgrade examples
 can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en

- -------------------------------------------------------------------------
subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8WU7f42jd0JmAcZARAnIWAJ9lexul5EiE+gOnfBg4igYrBu+33wCfa/GL
uPckZK7hdjwN5ChNPd0du7o=
=1pYS
-----END PGP SIGNATURE-----



Relevant Pages

  • [CLA-2003:738] Conectiva Security Announcement - pine
    ... Pine is a mail and news text based client developed by the Washington ... This update fixes two pine remote vulnerabilities found by ... The apt tool can be used to perform RPM packages upgrades: ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2002:551] Conectiva Linux Security Announcement - pine
    ... Pine is a mail and news text based client developed by the Washington ... All pine users should upgrade. ... DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2004:821] Conectiva Security Announcement - XFree86
    ... Greg MacManus from iDEFENSE Labs discoveredtwo vulnerabilities ... in the way the X server deals with font files. ... It is recommended that all XFree86 users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2004:847] Conectiva Security Announcement - php4
    ... Remote arbitrary code execution vulnerabilities and other ... It is recommended that all PHP users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2005:917] Conectiva Security Announcement - krb5
    ... It is recommended that all Kerberos users in Conectiva Linux upgrade ... UPDATED PACKAGES ... Detailed instructions regarding the use of apt and upgrade examples ...
    (Bugtraq)