LWN.net Logo

Gentoo alert 200305-06 (cdrtools)

From:  Daniel Ahlberg <aliz@gentoo.org>
To:  gentoo-announce@gentoo.org
Subject:  GLSA: cdrtools (200305-06.1)
Date:  Sun, 18 May 2003 14:18:13 +0200

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-06.1 - - - --------------------------------------------------------------------- PACKAGE : cdrtools SUMMARY : privelige escalation DATE : 2003-05-18 12:18 UTC EXPLOIT : local VERSIONS AFFECTED : <cdrtools-2.01_alpha14 FIXED VERSION : >=cdrtools-2.01_alpha14, =cdrtools-1.11.33-r1, =cdrtools-1.11.39-r1 CVE : CAN-2003-0289 - - - --------------------------------------------------------------------- Last advisory had the wrong url to the advisory. - -- Cdrecord isn't installed setuid root by default in Gentoo. Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105285564307225&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running app-cdr/cdrtools upgrade to one of the following versions: for users running xcdroast: cdrtools-1.11.33-r1 for sparc users: cdrtools-1.11.39-r1 for everyone else: cdrtools-2.01_alpha14 emerge sync emerge \=app-cdr/<your_version> emerge clean - - - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz - - - --------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE+x3oDfT7nyhUpoZMRAsCOAJ9D6RKDfWk7Ume0Ohxzjo565ag2nQCgvt7C ZB+8kPnl/YbP18hndes61HQ= =efSJ -----END PGP SIGNATURE-----


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds