[slackware-security] GDM security update (SSA:2003-236-01)

From: Slackware Security Team (security_at_slackware.com)
Date: 08/25/03

  • Next message: DigitalPranksters: "RealOne Player Allows Cross Zone and Domain Access"
    Date: Sun, 24 Aug 2003 15:48:28 -0700 (PDT)
    To: slackware-security@slackware.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    [slackware-security] GDM security update (SSA:2003-236-01)

    Upgraded gdm packages are available for Slackware 9.0 and -current.
    These fix a security issue where a local user may use GDM to read any
    file on the system.

    Here are the details from the Slackware 9.0 ChangeLog:
    +--------------------------+
    Sun Aug 24 14:36:29 PDT 2003
    patches/packages/gdm-2.4.1.6-i386-1.tgz: Upgraded to gdm-2.4.1.6.
      This fixes a bug where a local user may read any system file by making a
      symlink to it from $HOME/.xsession-errors and using GDM's error browser
      to read the file.
      (* Security fix *)
    +--------------------------+

    WHERE TO FIND THE NEW PACKAGES:
    +-----------------------------+

    Updated package for Slackware 9.0:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/gdm-2.4.1.6-i386-1.tgz

    Updated package for Slackware -current:
    ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/gnome/gdm-2.4.1.6-i486-1.tgz

    MD5 SIGNATURES:
    +-------------+

    Slackware 9.0 package:
    a5939f91ac56b5dd97d4a2013f099aed gdm-2.4.1.6-i386-1.tgz

    Slackware -current package:
    26459fb6dec7279fe4d80aba0b3ac4ff gdm-2.4.1.6-i486-1.tgz

    INSTALLATION INSTRUCTIONS:
    +------------------------+

    Upgrade using upgradepkg (as root):
    upgradepkg gdm-2.4.1.6-i386-1.tgz

    +-----+

    Slackware Linux Security Team
    http://slackware.com/gpg-key
    security@slackware.com

    +------------------------------------------------------------------------+
    | HOW TO REMOVE YOURSELF FROM THIS MAILING LIST: |
    +------------------------------------------------------------------------+
    | Send an email to majordomo@slackware.com with this text in the body of |
    | the email message: |
    | |
    | unsubscribe slackware-security |
    | |
    | You will get a confirmation message back. Follow the instructions to |
    | complete the unsubscription. Do not reply to this message to |
    | unsubscribe! |
    +------------------------------------------------------------------------+

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.2 (GNU/Linux)

    iD8DBQE/STINakRjwEAQIjMRAlDBAJ9zkONkmlbIRF6Lzj19I34gc884YwCghoPD
    ILS19+PLCWvT+zsIDm4Wcyw=
    =G/E+
    -----END PGP SIGNATURE-----


  • Next message: DigitalPranksters: "RealOne Player Allows Cross Zone and Domain Access"

    Relevant Pages

    • [slackware-security] kdelibs (SSA:2004-238-01)
      ... to fix security issues with URI handling. ... Here are the details from the Slackware 9.1 ChangeLog: ... Updated package for Slackware 9.0: ...
      (Bugtraq)
    • [slackware-security] sysklogd update (SSA:2004-124-02)
      ... to fix a security issue where a user could cause syslogd to crash. ... Here are the details from the Slackware 9.1 ChangeLog: ... Updated package for Slackware 8.1: ...
      (Bugtraq)
    • [slackware-security] apache (SSA:2004-133-01)
      ... We recommend that sites running Apache upgrade ... Here are the details from the Slackware 9.1 ChangeLog: ... These security fixes were backported from Apache 1.3.31: ... Updated package for Slackware 8.1: ...
      (Bugtraq)
    • [slackware-security] mc (SSA:2004-136-01)
      ... fix security issues that These could lead to a denial of service or the ... Sites that use mc should upgrade to the new mc package. ... Here are the details from the Slackware 9.1 ChangeLog: ... service or the execution of arbitrary code as the user running mc. ...
      (Bugtraq)
    • [slackware-security] lftp security update (SSA:2003-346-01)
      ... A security problem with lftp has been corrected with the release ... Here are the details from the Slackware 9.1 ChangeLog: ... this includes "security fixes in html ... WHERE TO FIND THE NEW PACKAGE: ...
      (Bugtraq)

  • Quantcast