LWN.net Logo

Pardus alert 2011-69 (rdesktop)

From:  Meltem Parmaksız <meltem@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2011-69] rdesktop: Directory Traversal vulnerability
Date:  Tue, 3 May 2011 13:57:38 +0300
Message-ID:  <201105031357.38952.meltem@pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2011-69 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2011-05-02 Type: Remote ------------------------------------------------------------------------ Summary ======= A vulnerability have been fixed in rdesktop which allows writing, reading and listing the content of the directories, all transparently. Description =========== CVE-2011-1595: Directory Traversal vulnerability which affects an rDesktop client (I believe other products that use the same code will have the same issue), which will allow someone connecting to a compromised server (RDP server) or via a MITM vulnerability to access any file he desires on the user's computer. Affected packages: Pardus 2009: rdesktop, all before 1.7.0-5-5 Resolution ========== There are update(s) for rdesktop. You can update them via Package Manager or with a single command from console: pisi up rdesktop References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=17861 * https://bugzilla.redhat.com/show_bug.cgi?id=676252 ------------------------------------------------------------------------ _______________________________________________ Pardus-Security mailing list Pardus-Security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds