Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Gentoo: 202905-12 High Security Vulnerability in gpg Setgid Exposed

gentoo
Calendar Grey July 19, 2003
Dist Gentoo Esm H88
GENTOO LINUX SECURITY ANNOUNCEMENT 200307-06 PACKAGE : gnupg SUMMARY : gpg setgid DATE : 2003-07-19
gpg needs to be setuid to make use of protected memory space, however thesetgid bit allowed gpg user to overwrite goup root writable files and istherefore unnecessary.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200307-06
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
gpg needs to be setuid to make use of protected memory space, however the setgid bit allowed gpg user to overwrite goup root writable files and is therefor unnecessary.
SOLUTION
It is recommended that all Gentoo Linux users who are running app-crypt/gnupg upgrade to gnupg-1.2.2-r1 as follows
emerge sync emerge gnupg emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at taviso@gentoo.org - - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : gnupg
SUMMARY : gpg setgid
DATE : 2003-07-19 14:27 UTC
EXPLOIT : local
VERSIONS AFFECTED : =gnupg-1.2.2-r1
CVE :

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here