Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Ubuntu 13.04 on me high-end box - Horrible
· NVIDIA GeForce Chips Comparison Table and more
· CSF 6.09 released
· Microsoft and Google agree to build YouTube app for Windows Phone 8
· OS X 10.8.4 Build 12E55 Seeded to Developers
· Wine 1.5.31 released
· Libxvmc/Libx11 Updates for Debian
· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?

Upcoming News
· Logitech k310 Washable Keyboard
· [Tech ARP] BIOS Option Of The Week - Hardware Prefetcher
· SuperTooth HD VOICE Bluetooth Speakerphone Review @ TestFreaks
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0
· [security-announce] SUSE-SU-2013:0819-2: critical: Security update for Linux kernel

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Easy to watch UFC 160 Live streaming
by: julianbarter0r
on: 2013-05-25 11:29
0 replies, 19 views

· Easy to watch UFC 160 Live Stream online
by: julianbarter0r
on: 2013-05-25 11:28
0 replies, 24 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6509 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 719 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4608 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » October 2009 » USN-847-2: devscripts vulnerability

USN-847-2: devscripts vulnerability

Posted by Bob on: 10/09/2009 03:40 PM [ Print | 0 comment(s) ]

A new devscripts vulnerability update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-847-2 October 09, 2009
devscripts vulnerability
CVE-2009-2946
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
devscripts 2.9.10-0ubuntu0.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

USN-847-1 fixed vulnerabilities in devscripts. This update provides the
corresponding updates for Ubuntu 6.06 LTS.

Original advisory details:

Raphael Geissert discovered that uscan, a part of devscripts, did not
properly sanitize its input when processing pathnames. If uscan processed a
crafted filename for a file on a remote server, an attacker could execute
arbitrary code with the privileges of the user invoking the program.


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/d/devscripts/devscripts_2.9.10-0ubuntu0.1.dsc
Size/MD5: 715 46fa68657534c79a7742a7561d149764
http://security.ubuntu.com/ubuntu/pool/main/d/devscripts/devscripts_2.9.10-0ubuntu0.1.tar.gz
Size/MD5: 341732 84e4aacdd4495ad4df1e5ec2742bbc7e

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/d/devscripts/devscripts_2.9.10-0ubuntu0.1_amd64.deb
Size/MD5: 296176 c136944ba913bad8591d288ad78ac856

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/d/devscripts/devscripts_2.9.10-0ubuntu0.1_i386.deb
Size/MD5: 295818 44d8620d6604b9ac51f52e4d4cd0c7dc

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/d/devscripts/devscripts_2.9.10-0ubuntu0.1_powerpc.deb
Size/MD5: 298350 a0bdd4a041737e983350b94cae6273d3

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/d/devscripts/devscripts_2.9.10-0ubuntu0.1_sparc.deb
Size/MD5: 296218 613ed8459d8ac5ad221d71ec24c08464



--DqhR8hV3EnoxUkKN
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkrPSU4ACgkQW0JvuRdL8BocAwCfQxe4wqG2buhpovapj7T+8yt0
wLwAn3hkPKsRlSkAzir7WQaAyQaojasY
=3R8c
-----END PGP SIGNATURE-----


Bookmark and Share

« Songbird 1.4.0 Beta 3 · PrimoPDF 5.0.0.19 »

Linux Compatible » News » October 2009 » USN-847-2: devscripts vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition