Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?
· New Colors Rumored for iPhone 5S and Lower-Cost iPhone, Dual LED Flash for iPhone 5S?
· NVIDIA GeForce 320.18 WHQL Drivers
· 20 Debian Updates
· OCZ Vertex 450 Series Solid State Drives announced
· NVIDIA GeForce GTX 780 Reviews Roundup
· Apple's 'iWatch' to come in late 2014 with focus on biometrics, analyst says
· Windows 8.1 laptops with AMDs new chips to support wireless display
· HP $399 touchscreen laptop breaks price barrier

Upcoming News
· OCZ Power Supply Roundup
· Sitecom Wi-Fi Router X6 N900 (WLR-6100) Review @ Madshrimps
· AMD A4-5000 Review: The affordable ultraportable APU
· Ninjalane Podcast - Paintball at SuperGame
· 4TB Seagate Desktop HDD ST4000DM000 @ Benchmark Reviews
· REVIEW: Nvidia GeForce GTX 780 @ PureOverclock
· iStarUSA BPU-340SATA Military Grade Drive Enclosure
· A Futurelooks New Flash - Futurelooks Weekly Giveawa?= y 2 of 3 – Win an ADATA XPG v1.0 1866mhz 8GB (4GB x 2) Mem?= ory Kit
· Security issue in livecd-tools causes password issue in Fedora cloud images
· Gigabyte C847N Motherboard @ Hardware Secrets

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6462 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 702 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4581 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 775 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1156 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » November 2004 » DSA 583-1: New lvm10 packages fix insecure temporary directory

DSA 583-1: New lvm10 packages fix insecure temporary directory

Posted by Philipp Esselbach on: 11/03/2004 05:13 AM [ Print | 0 comment(s) ]

New lvm10 packages are available for Debian GNU/Linux

---------------------------------------------------------------------------
Debian Security Advisory DSA 583-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
November 3rd, 2004 http://www.debian.org/security/faq
---------------------------------------------------------------------------

Package : lvm10
Vulnerability : insecure temporary directory
Problem-Type : local
Debian-specific: no
CVE ID : CAN-2004-0972
Debian Bug : 279229

Trustix developers discovered insecure temporary file creation in a supplemental script in the lvm10 package that didn't check for existing temporary directories, allowing local users to overwrite files via a symlink attack.

For the stable distribution (woody) this problem has been fixed in version 1.0.4-5woody2.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your lvm10 package.




Upgrade Instructions
---------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
---------------------------------

Source archives:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2.dsc
Size/MD5 checksum: 561 e5870dc0de9c2e47201d8f7dab0af624
http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2.diff.gz
Size/MD5 checksum: 7964 a9eb089d9ed491a569889a1ca0bd1be4
http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4.orig.tar.gz
Size/MD5 checksum: 373104 9081ae96e94bef6c4c2e8c5f2dcc654c

Alpha architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_alpha.deb
Size/MD5 checksum: 1199872 95321cf32c955269ef5e22eb35177c85

ARM architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_arm.deb
Size/MD5 checksum: 2078632 02b80c8320640d88da71503228c088b7

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_i386.deb
Size/MD5 checksum: 1987842 546d12296630017a50ab164b385fbfb4

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_ia64.deb
Size/MD5 checksum: 1633240 da929a10feb0e9d5f7869034fc4a311b

HP Precision architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_hppa.deb
Size/MD5 checksum: 2110980 07bc200b8abbfc9b050df98794fc0bf9

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_m68k.deb
Size/MD5 checksum: 1995258 504c02f300ef94797076b24aeffac698

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_mips.deb
Size/MD5 checksum: 818778 c11595f00382bee32dbf839461e173eb

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_mipsel.deb
Size/MD5 checksum: 800362 21d8ec07ef0d6592fce08921e3e11b6f

PowerPC architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_powerpc.deb
Size/MD5 checksum: 2213258 9b92a1958c65664c6256c41a7e29fba7

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_s390.deb
Size/MD5 checksum: 2043052 9395c323525bc9cfe04bf045ba76dd30

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/l/lvm10/lvm10_1.0.4-5woody2_sparc.deb
Size/MD5 checksum: 2095860 ba67c6e9188fad3ca653279f199188a6


These files will probably be moved into the stable distribution on its next update.


Bookmark and Share

« Sapphire Radeon X800XT PCI Express Review · FPGamerunner a Real Exercise for FPS Gamers »

Linux Compatible » News » November 2004 » DSA 583-1: New lvm10 packages fix insecure temporary directory
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition