______________________________________________________________________ Mandrake Linux Security Update Advisory ______________________________________________________________________ Package name: usermode Advisory ID: MDKSA-2003:031 Date: March 12th, 2003 Affected versions: 8.1, 8.2, 9.0, Corporate Server 2.1, Multi Network Firewall 8.2 ______________________________________________________________________ Problem Description: The /usr/bin/shutdown command that comes with the usermode package can be executed by local users to shutdown all running processes and drop into a root shell. This command is not really needed to shutdown a system, so it has been removed and all users are encouraged to upgrade. Please note that the user must have local console access in order to obtain a root shell in this fashion. ______________________________________________________________________ References: ______________________________________________________________________ Updated Packages: Corporate Server 2.1: 6b3efb01bca77c598bfed862df7a10fe corporate/2.1/RPMS/usermode-1.55-8.1mdk.i586.rpm eda24e3cdb96a6171e5b6ed7e6b1da2b corporate/2.1/RPMS/usermode-consoleonly-1.55-8.1mdk.i586.rpm 498c7c44ab984017a38662202ec7e61f corporate/2.1/SRPMS/usermode-1.55-8.1mdk.src.rpm Mandrake Linux 8.1: d338123f2d65b6d5e37c3475cb658720 8.1/RPMS/usermode-1.42-8.1mdk.i586.rpm 1f56c7f08d8c1cd5f984e150c0c7ab98 8.1/SRPMS/usermode-1.42-8.1mdk.src.rpm Mandrake Linux 8.1/IA64: f5d33ef9c30d28a9a01fc6e277b5b703 ia64/8.1/RPMS/usermode-1.42-8.1mdk.ia64.rpm 1f56c7f08d8c1cd5f984e150c0c7ab98 ia64/8.1/SRPMS/usermode-1.42-8.1mdk.src.rpm Mandrake Linux 8.2: ab8e859ccce7f45022ba698742f70552 8.2/RPMS/usermode-1.44-4.1mdk.i586.rpm 18693e77214c918ce8aadc405c9347c3 8.2/RPMS/usermode-consoleonly-1.44-4.1mdk.i586.rpm c75d3d564384692e412fb24ad885193c 8.2/SRPMS/usermode-1.44-4.1mdk.src.rpm Mandrake Linux 8.2/PPC: 152e076d46e0eb5b37784005d0dfabcc ppc/8.2/RPMS/usermode-1.44-4.1mdk.ppc.rpm 228e12c9af55c32e814a9d712c10da53 ppc/8.2/RPMS/usermode-consoleonly-1.44-4.1mdk.ppc.rpm c75d3d564384692e412fb24ad885193c ppc/8.2/SRPMS/usermode-1.44-4.1mdk.src.rpm Mandrake Linux 9.0: 6b3efb01bca77c598bfed862df7a10fe 9.0/RPMS/usermode-1.55-8.1mdk.i586.rpm eda24e3cdb96a6171e5b6ed7e6b1da2b 9.0/RPMS/usermode-consoleonly-1.55-8.1mdk.i586.rpm 498c7c44ab984017a38662202ec7e61f 9.0/SRPMS/usermode-1.55-8.1mdk.src.rpm Multi Network Firewall 8.2: 18693e77214c918ce8aadc405c9347c3 mnf8.2/RPMS/usermode-consoleonly-1.44-4.1mdk.i586.rpm c75d3d564384692e412fb24ad885193c mnf8.2/SRPMS/usermode-1.44-4.1mdk.src.rpm ______________________________________________________________________ Bug IDs fixed (see https://qa.mandrakesoft.com for more information): 408 - vulnerability fixed in RedHat two years ago still in Mandrake 8.2 ______________________________________________________________________ To upgrade automatically, use MandrakeUpdate. The verification of md5 checksums and GPG signatures is performed automatically for you. If you want to upgrade manually, download the updated package from one of our FTP server mirrors and upgrade with "rpm -Fvh *.rpm". A list of FTP mirrors can be obtained from: http://www.mandrakesecure.net/en/ftp.php Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command: rpm --checksig <filename> All packages are signed by MandrakeSoft for security. You can obtain the GPG public key of the Mandrake Linux Security Team from: https://www.mandrakesecure.net/RPM-GPG-KEYS Please be aware that sometimes it takes the mirrors a few hours to update. You can view other update advisories for Mandrake Linux at: http://www.mandrakesecure.net/en/advisories/ MandrakeSoft has several security-related mailing list services that anyone can subscribe to. Information on these lists can be obtained by visiting: http://www.mandrakesecure.net/en/mlist.php If you want to report vulnerabilities, please contact security_linux-mandrake.com Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team <security linux-mandrake.com>
Mandrake Linux Advisory: usermode
By
Get the Free Newsletter!
Subscribe to Developer Insider for top news, trends, & analysis