|
|
Subscribe / Log in / New account

Slackware alert SSA:2024-275-03 (cryfs)

From:  Slackware Security Team <security@slackware.com>
To:  slackware-security@slackware.com
Subject:  [slackware-security] rpath security issues (SSA:2024-275-03)
Date:  Tue, 01 Oct 2024 12:05:36 -0700
Message-ID:  <alpine.LNX.2.02.2410011205210.28145@connie.slackware.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] rpath security issues (SSA:2024-275-03) Several packages have been updated for Slackware 15.0 and -current to fix rpath security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ Several ELF objects were found to have rpaths pointing into /tmp, a world writable directory. This could have allowed a local attacker to launch denial of service attacks or execute arbitrary code when the affected binaries are run by placing crafted ELF objects in the /tmp rpath location. All rpaths with an embedded /tmp path have been scrubbed from the binaries, and makepkg has gained a lint feature to detect these so that they won't creep back in. extra/llvm-17.0.6-i586-2_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/cryfs-0.10.3-i586-5_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/espeak-ng-1.50-i586-4_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/libvncserver-0.9.13-i586-4_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/marisa-0.2.6-i586-5_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/mlt-7.4.0-i586-2_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/openobex-1.7.2-i586-6_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) patches/packages/pkgtools-15.0-noarch-44_slack15.0.txz: Rebuilt. makepkg: when looking for ELF objects with --remove-rpaths or --remove-tmp-rpaths, avoid false hits on files containing 'ELF' as part of the directory or filename. Also warn about /tmp rpaths after the package is built. patches/packages/spirv-llvm-translator-13.0.0-i586-2_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) testing/packages/llvm-18.1.8-i686-2_slack15.0.txz: Rebuilt. Remove rpaths from binaries. (* Security fix *) +--------------------------+ Installation instructions: +------------------------+ Upgrade the packages using upgradepkg or slackpkg. +-----+ Slackware Linux Security Team http://slackware.com/gpg-key security@slackware.com +------------------------------------------------------------------------+ | To leave the slackware-security mailing list: | +------------------------------------------------------------------------+ | Send an email to majordomo@slackware.com with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back containing instructions to | | complete the process. Please do not reply to this email address. | +------------------------------------------------------------------------+ -----BEGIN PGP SIGNATURE----- iF0EARECAB0WIQTsVknaQB4iq/pnNu9qRGPAQBAiMwUCZvw/FAAKCRBqRGPAQBAi M59tAJ97gmeZYBaMF5U3oWQyssBuHsw3gACfd4PLvs617AjxsfWV5eVkLHEdS/o= =uXJ3 -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds