|
|||||||||||
|
[ MDKSA-2007:134 ] - Updated xfsdump packages fix unsafe temporary directory creation issue
From: <security(at)mandriva.com>
Date: Thu Jun 21 2007 - 19:58:30 EDT -----BEGIN PGP SIGNED MESSAGE-----
Mandriva Linux Security Advisory MDKSA-2007:134http://www.mandriva.com/security/ Package : xfsdump Date : June 21, 2007 Affected: 2007.0, 2007.1, Corporate 4.0 Problem Description: xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems. Updated packages have been patched to prevent this issue. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2654 Updated Packages:
Mandriva Linux 2007.0:
Mandriva Linux 2007.0/X86_64:
Mandriva Linux 2007.1:
Mandriva Linux 2007.1/X86_64:
Corporate 4.0:
Corporate 4.0/X86_64:
To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact security_(at)_mandriva.com
Type Bits/KeyID Date User ID
iD8DBQFGeuXRmqjQ0CJFipgRAj0WAKC80tS2iWWmAFxYHuQ0eCM/EzXdvwCeO4AR
kWhnAnTov8Js78hM1jrN/ps=
This archive was generated by hypermail 2.1.8 : Fri Jun 22 2007 - 11:40:02 EDT |
||||||||||
|
|||||||||||