[CLA-2004:833] Conectiva Security Announcement - mc

From: Conectiva Updates (secure_at_conectiva.com.br)
Date: 03/31/04

  • Next message: Drew Copley: "RE: Followup: vuln in WinBlox monitor for winnt"
    Date: Wed, 31 Mar 2004 15:04:09 -0300
    To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT
    - --------------------------------------------------------------------------

    PACKAGE : mc
    SUMMARY : Buffer overflow vulnerability
    DATE : 2004-03-31 15:03:00
    ID : CLA-2004:833
    RELEVANT
    RELEASES : 8, 9

    - -------------------------------------------------------------------------

    DESCRIPTION
     Midnight Commander (MC) is a visual shell and a file manager for text
     consoles.
     
     This update fixes a buffer overflow vulnerability[1] in the code that
     handles symlinks in the virtual filesystem module. An attacker could
     create a specially crafted archive (like a .tar.gz or a cpio file)
     containing symlinks that when opened by an mc user would trigger the
     execution of arbitrary code with its privileges.
     
     The Common Vulnerabilities and Exposures project (cve.mitre.org) has
     assigned the name CAN-2003-1023 to this issue[2].

    SOLUTION
     All users of the mc package should upgrade.
     
     
     REFERENCES
     1.http://www.securityfocus.com/bid/8658/
     2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-1023

    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/8/RPMS/gmc-4.5.55-6U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/mc-4.5.55-6U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/mcserv-4.5.55-6U80_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/mc-4.5.55-6U80_1cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/gmc-4.5.55-19421U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/mc-4.5.55-19421U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/mcserv-4.5.55-19421U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/mc-4.5.55-19421U90_1cl.src.rpm

    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:

     - run: apt-get update
     - after that, execute: apt-get upgrade

     Detailed instructions regarding the use of apt and upgrade examples
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en

    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en

    - -------------------------------------------------------------------------
    Copyright (c) 2004 Conectiva Inc.
    http://www.conectiva.com

    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
    unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQFAawgY42jd0JmAcZARAhCFAKCBwWmbCSxwr4olps6xfWoeyYsWCwCgg0fi
    j8XBi7W8ThR/khEnbKciptc=
    =Ar1F
    -----END PGP SIGNATURE-----


  • Next message: Drew Copley: "RE: Followup: vuln in WinBlox monitor for winnt"

    Relevant Pages

    • [CLA-2003:664] Conectiva Security Announcement - radiusd-cistron
      ... SUMMARY: Buffer overflow vulnerability ... The apt tool can be used to perform RPM packages upgrades: ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2002:542] Conectiva Linux Security Announcement - gv/kghostview
      ... Zen Parse founda buffer overflow vulnerability in gv version ... All gv and kdegraphics users are advised to upgrade. ... DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:773] Conectiva Security Announcement - libnids
      ... Robert Watson found a buffer overflow vulnerability in the code ... responsible for TCP reassembly of libnids. ... UPDATED PACKAGES ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:734] Conectiva Security Announcement - pam_smb
      ... SUMMARY: Remote buffer overflow vulnerability ... A buffer overflow vulnerability has been discovered in the pam_smb ... The apt tool can be used to perform RPM packages upgrades: ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2004:821] Conectiva Security Announcement - XFree86
      ... Greg MacManus from iDEFENSE Labs discoveredtwo vulnerabilities ... in the way the X server deals with font files. ... It is recommended that all XFree86 users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)