To: [email protected]Subject: [ MDKSA-2006:083 ] - Updated gdm package fixes symlink attack vulnerability
Date: Tue, 9 May 2006 19:36:01 -0600
From: [email protected]
Reply-To: <xsecurity@mandriva.com.>
Message-Id: <E1FddcP-0006pb-HK@mercury.mandriva.com.>
Sender: QATeam User <qateam@mercury.mandriva.com.>
X-Virus-Scanned: antivirus-gw at tyumen.ru
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:083
http://www.mandriva.com/security/
_______________________________________________________________________
Package : gdm
Date : May 9, 2006
Affected: 2006.0
_______________________________________________________________________
Problem Description:
A race condition in daemon/slave.c in gdm before 2.14.1 allows local
users to gain privileges via a symlink attack when gdm performs chown
and chgrp operations on the .ICEauthority file.
Packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1057
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2006.0:
d252ac2b6b8e0ea6c42b97d12154e054 2006.0/RPMS/gdm-2.8.0.4-1.1.20060mdk.i586.rpm
06c26efefc15238226177bcf2b557f98 2006.0/RPMS/gdm-Xnest-2.8.0.4-1.1.20060mdk.i586.rpm
7061440dac40a07c55a14e2a1f673536 2006.0/SRPMS/gdm-2.8.0.4-1.1.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
aaa20636b30f9b8df2c9c538b7c77635 x86_64/2006.0/RPMS/gdm-2.8.0.4-1.1.20060mdk.x86_64.rpm
ac0ab88f60162481348072b67151883a x86_64/2006.0/RPMS/gdm-Xnest-2.8.0.4-1.1.20060mdk.x86_64.rpm
7061440dac40a07c55a14e2a1f673536 x86_64/2006.0/SRPMS/gdm-2.8.0.4-1.1.20060mdk.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFEYRhbmqjQ0CJFipgRAg2jAKCoZJtEFmoLieJFZhMjpKS+LHZcwgCdEvsZ
G+JunIe1aW/YTAb3h+Dsqto=
=+FEO
-----END PGP SIGNATURE-----