[slackware-security] gdm security update (SSA:2003-300-01)

From: Slackware Security Team (security_at_slackware.com)
Date: 10/27/03

  • Next message: Young, Keith: "Nachi/Welchia/LovSan.D version 2 appears to be spreading"
    Date: Mon, 27 Oct 2003 12:07:30 -0800 (PST)
    To: slackware-security@slackware.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    [slackware-security] gdm security update (SSA:2003-300-01)

    GDM is the GNOME Display Manager, and is commonly used to provide
    a graphical login for local users.

    Upgraded gdm packages are available for Slackware 9.0, 9.1,
    and -current. These fix two vulnerabilities which could allow a local
    user to crash or freeze gdm, preventing access to the machine until a
    reboot. Sites using gdm should upgrade, especially sites such as
    computer labs that use gdm to provide public or semi-public access.

    More details about these issues may be found in the Common
    Vulnerabilities and Exposures (CVE) database:

      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0793
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0794

    Here are the details from the Slackware 9.1 ChangeLog:
    +--------------------------+
    Wed Oct 22 12:10:11 PDT 2003
    patches/packages/gdm-2.4.4.5-i486-1.tgz: Upgraded to gdm-2.4.4.5. This
      fixes a bug which can allow a local user to crash gdm, preventing
      access until the machine is rebooted.
      (* Security fix *)
    +--------------------------+

    WHERE TO FIND THE NEW PACKAGES:
    +-----------------------------+

    Updated package for Slackware 9.0:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/gdm-2.4.1.7-i386-1.tgz

    Updated package for Slackware 9.1:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/gdm-2.4.4.5-i486-1.tgz

    Updated package for Slackware -current:
    ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/gnome/gdm-2.4.4.5-i486-1.tgz

    MD5 SIGNATURES:
    +-------------+

    Slackware 9.0 package:
    ba1123ac6d5f56401cd80efcabcd9502 gdm-2.4.1.7-i386-1.tgz

    Slackware 9.1 package:
    bb34febec76f6c61f9d3740a95082db8 gdm-2.4.4.5-i486-1.tgz

    Slackware -current package:
    bb34febec76f6c61f9d3740a95082db8 gdm-2.4.4.5-i486-1.tgz

    INSTALLATION INSTRUCTIONS:
    +------------------------+

    First, stop gdm. If you're using runlevel 4 to start gdm, issue the
    command to change to a console-based runlevel:

    # telinit 3

    Next, upgrade gdm as root:

    # upgradepkg gdm-2.4.4.5-i486-1.tgz

    Finally, restart gdm:

    # telinit 4

    +-----+

    Slackware Linux Security Team
    http://slackware.com/gpg-key
    security@slackware.com

    +------------------------------------------------------------------------+
    | HOW TO REMOVE YOURSELF FROM THIS MAILING LIST: |
    +------------------------------------------------------------------------+
    | Send an email to majordomo@slackware.com with this text in the body of |
    | the email message: |
    | |
    | unsubscribe slackware-security |
    | |
    | You will get a confirmation message back. Follow the instructions to |
    | complete the unsubscription. Do not reply to this message to |
    | unsubscribe! |
    +------------------------------------------------------------------------+

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)

    iD8DBQE/nXl4akRjwEAQIjMRAk89AJ9hJTecFHNiadpZLBZQwBgGajxFAACglRyO
    ELDLA6Ms4OxM7TZ2yS3mVXU=
    =Cya4
    -----END PGP SIGNATURE-----


  • Next message: Young, Keith: "Nachi/Welchia/LovSan.D version 2 appears to be spreading"

    Relevant Pages

    • Re: machine
      ... You can use Slackware's package management system, ... installpkg - Install a Slackware package ... You can compile the program from the source. ... > install something, something else had to get uninstalled, ...
      (alt.os.linux)
    • Re: Problems when booting up...
      ... bar, but the bar gets just about to the end, then it reverts back ... GUI login (GDM, KDM, XDM), then first you need to have the ... appropriate package installed, and active in /etc/rc2.d/ ... (installing one of the *dm packages _should_ set up the init ...
      (Ubuntu)
    • [slackware-security] metamail security update (SSA:2004-049-02)
      ... Metamail is a set of utilities for processing MIME mail. ... overflows which could lead to unauthorized code execution. ... Here are the details from the Slackware 9.1 ChangeLog: ... WHERE TO FIND THE NEW PACKAGE: ...
      (Bugtraq)
    • [slackware-security] rsync update (SSA:2004-124-01)
      ... When running an rsync server without the chroot option ... Any sites running rsync in that mode should upgrade right away (and should ... Here are the details from the Slackware 9.1 ChangeLog: ... Updated package for Slackware 8.1: ...
      (Bugtraq)
    • Re: Slackware jdk packages
      ... >> I'm a new user to Slackware (Slax) but not Linux. ... >> I'm looking for a good resource on how to build my own Slackware ... >> create a JDK package and a NetBeans package. ... > Debian system might be difficult or more than difficult. ...
      (comp.os.linux.questions)