Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Gentoo: 202305-09 Warning Issued for Detected OS Vulnerability

gentoo
Calendar Grey May 19, 2003
Dist Gentoo Esm H88
A local root exploit is detected in lv command in Gentoo, upgrade recommended to mitigate risks.
Previous versions of lv read the file .lv in the current directory

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200305-07


Previous versions of lv read the file .lv in the current directory. Becuse this file could be created by other users and could contain malicious commands to execute upon viewing certain files this is considered a potential local root exploit.
SOLUTION
It is recommended that all Gentoo Linux users who are running app-text/lv upgrade to lv-4.49.5 as follows
emerge sync emerge lv emerge clean
aliz@gentoo.org - GnuPG key is available at nakano@gentoo.org

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
important
Lowest
Low
Medium
High
Critical

PACKAGE : lv
SUMMARY : arbitrary command execution
DATE : 2003-05-19 07:10 UTC
EXPLOIT : local
VERSIONS AFFECTED : =lv-4.49.5
CVE : CAN-2003-0188

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here