LWN.net Logo

Gentoo alert 200308-02 (semi)

From:  aliz@gentoo.org (Daniel Ahlberg)
To:  gentoo-announce@gentoo.org
Subject:  [gentoo-announce] GLSA: semi (200308-02)
Date:  Thu, 14 Aug 2003 21:30:29 +0200 (CEST)

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200308-02 - - - ---------------------------------------------------------------------           PACKAGE : semi           SUMMARY : insecure temporary files creation              DATE : 2003-08-14 19:30 UTC           EXPLOIT : local VERSIONS AFFECTED : <semi-1.14.5-r1     FIXED VERSION : >=semi-1.14.5-r1               CVE : CAN-2003-0440 - - - --------------------------------------------------------------------- quote from CVE: "The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files." SOLUTION It is recommended that all Gentoo Linux users who are running app-emacs/semi upgrade to semi-1.14.5-r1 as follows emerge sync emerge semi emerge clean - - - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz usata@gentoo.org - - - --------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE/O+NVfT7nyhUpoZMRAlo0AJ0ZwAWeNbss87RYJ5UaSvHXkF3n7wCfbZTw eDaHCxhEc1WGSEoQpcL+/J8= =ThD4 -----END PGP SIGNATURE-----


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds