[CLA-2004:909] Conectiva Security Announcement - netpbm

From: Conectiva Updates (secure_at_conectiva.com.br)
Date: 12/29/04

  • Next message: Thierry Carrez: "[ GLSA 200412-25 ] CUPS: Multiple vulnerabilities"
    Date: Wed, 29 Dec 2004 15:23:11 -0200
    To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT
    - --------------------------------------------------------------------------

    PACKAGE : netpbm
    SUMMARY : Insecure temporary file creation
    DATE : 2004-12-29 14:59:00
    ID : CLA-2004:909
    RELEVANT
    RELEASES : 9, 10

    - -------------------------------------------------------------------------

    DESCRIPTION
     netpbm[1] are tools for manipulating graphic files in many formats.
     
     Utilities provided by the netpbm package prior to the 9.25 version
     contain defects[2] in temporary file handling. They create temporary
     files with predictable names without checking if the target file
     already exists.

    SOLUTION
     It is recommended that all netpbm users upgrade their packages.
     
     
     REFERENCES
     1.http://netpbm.sourceforge.net/
     2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924

    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/10/SRPMS/netpbm-9.20-58886U10_1cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/libnetpbm9-9.20-58886U10_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/libnetpbm9-devel-9.20-58886U10_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/libnetpbm9-devel-static-9.20-58886U10_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/netpbm-9.20-58886U10_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/netpbm-9.20-27817U90_1cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/libnetpbm9-9.20-27817U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/libnetpbm9-devel-9.20-27817U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/libnetpbm9-devel-static-9.20-27817U90_1cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/netpbm-9.20-27817U90_1cl.i386.rpm

    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:

     - run: apt-get update
     - after that, execute: apt-get upgrade

     Detailed instructions regarding the use of apt and upgrade examples
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en

    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en

    - -------------------------------------------------------------------------
    Copyright (c) 2004 Conectiva Inc.
    http://www.conectiva.com

    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
    unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQFB0uf+42jd0JmAcZARAiI5AJ9tT4WpAC2uifrSHqVB/QowfLuG8wCgjll9
    Dn54cZwt5Ueifc4ipNBS9ow=
    =bmaV
    -----END PGP SIGNATURE-----


  • Next message: Thierry Carrez: "[ GLSA 200412-25 ] CUPS: Multiple vulnerabilities"

    Relevant Pages