Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Contribute
Contribute
Link to Us
Linux Jobs

Partner Sites
JustLinux.com
Linux Planet
PHPBuilder
Technology Jobs

Top White Papers

More on LinuxToday


Trustix Secure Linux Security Advisory: Util-linux

Oct 18, 2001, 05:47 (0 Talkback[s])
Date: Wed, 17 Oct 2001 16:21:12 +0200
To: tsl-announce@trustix.com
Subject: TSLSA-2001-0025 - util-linux
From: Trustix Secure Linux Advisor 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Security Advisory #2001-0025

Package name:      Util-linux
Summary:           Possible to gain some other user's credentials
Date:              2001-10-17
Affected versions: TSL 1.5

- --------------------------------------------------------------------------

Problem description:
  The "login" program in util-linux stored the user's credentials in a
  static buffer that could later be reused in other PAM calls issued on
  behalf of other users.  This could lead to a user gaining access to
  other accounts.
  Note that this is not possible by default.

Action:
  We recommend that all systems with this package installed are upgraded.


Location:
  All TSL updates are available from
  <URI:http://www.trustix.net/pub/Trustix/updates/>
  <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>


Automatic updates:
  Users of the SWUP tool, can enjoy having updates automatically
  installed using 'swup --upgrade'.

  Get SWUP from:
  <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>


Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.net/support/>


Verification:
  This advisory along with all TSL packages are signed with the TSL sign key.
  This key available from:
  <URI:http://www.trustix.net/TSL-GPG-KEY>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.net/errata/trustix-1.5/>
  or directly at
  <URI:http://www.trustix.net/errata/misc/2001/TSL-2001-0024-postfix.asc.txt>

MD5sums of the packages:
- --------------------------------------------------------------------------
ebdfde806ab5d2d67c25ffd1a90bb8aa  ./1.5/SRPMS/util-linux-2.11f-6tr.src.rpm
d96660d42ee2901c18577e26616cabdf  ./1.5/RPMS/util-linux-2.11f-6tr.i586.rpm
4a7a357bf1ad7e7999a39c508326b155  ./1.5/RPMS/mount-2.11f-6tr.i586.rpm
94dc41a4acf854f7bfff2276393ccd04  ./1.5/RPMS/losetup-2.11f-6tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE7zYOTwRTcg4BxxS0RAvQ7AJwJEhZEWjPZ0pN1TIaaqFkOUIs7gACfTrpt
JIfWCjwVk0Q2BHt7mRJMJ1s=
=LPnb
-----END PGP SIGNATURE-----