LWN.net Logo

Gentoo alert 200305-03 (kopete)

From:  Daniel Ahlberg <aliz@gentoo.org>
To:  gentoo-announce@gentoo.org
Subject:  GLSA: kopete (200305-03)
Date:  Wed, 14 May 2003 09:39:51 +0200

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-03 - - - --------------------------------------------------------------------- PACKAGE : kopete SUMMARY : Unsafe command line cleansing DATE : 2003-05-14 07:39 UTC EXPLOIT : remote VERSIONS AFFECTED : <kopete-0.6.2 FIXED VERSION : >=kopete-0.6.2 CVE : CAN-2003-0256 - - - --------------------------------------------------------------------- The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands. SOLUTION It is recommended that all Gentoo Linux users who are running net-im/kopete upgrade to kopete-0.6.2 as follows: emerge sync emerge kopete emerge clean - - - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz - - - --------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE+wfLGfT7nyhUpoZMRAoKwAJ99Gdwhcy436LanEEvAmWh/lgdvaQCgv8yw uo9SkNlFO2fkO41LozwZTPs= =r/Ih -----END PGP SIGNATURE-----


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds