Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo: 200304-09 Critical Advisory: Mgetty Spool Directory Risks

gentoo
Calendar Grey April 28, 2003
Dist Gentoo Esm H88
Arch Linux users should upgrade their package manager now to address critical security vulnerabilities related to improper input handling and unsecured installation directories
World-writable spool directory and buffer overflow in cnd-program have been fixed

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200304-09
- - ---------------------------------------------------------------------
    FIXED VERSION : >=mgetty-1.1.29

- - ---------------------------------------------------------------------
* faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to modify fax transmission privileges.
* Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Caller ID string with a long CallerName argument.
SOLUTION
It is recommended that all Gentoo Linux users who are running net-dialup/mgetty upgrade to mgetty-1.1.30 as follows:
emerge sync emerge mgetty emerge clean


Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : mgetty
SUMMARY : buffer overflow, insecure spool dir
DATE : 2003-04-28 10:17 UTC
EXPLOIT : remote
VERSIONS AFFECTED :
CVE : CAN-2002-1391 CAN-2002-1392

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here