SciLinux: CVE-2008-1951 sblim SL4.x, SL5.x i386/x86_64
Summary
Date: Wed, 25 Jun 2008 16:46:44 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for sblim on SL4.x, SL5.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Important: sblim security updateIssue date: 2008-06-24CVE Names: CVE-2008-1951It was discovered that certain sblim libraries had an RPATH (runtimelibrary search path) set in the ELF (Executable and Linking Format) header.This RPATH pointed to a sub-directory of a world-writable, temporarydirectory. A local user could create a file with the same name as a libraryrequired by sblim (such as libc.so) and place it in the directory definedin the RPATH. This file could then execute arbitrary code with theprivileges of the user running an application that used sblim (egtog-pegasus). (CVE-2008-1951)SL 4.x SRPMS:sblim-1-13a.el4_6.1.src.rpm i386:sblim-cmpi-base-1.5.4-13a.el4_6.1.i386.rpmsblim-cmpi-base-devel-1.5.4-13a.el4_6.1.i386.rpmsblim-cmpi-base-test-1.5.4-13a.el4_6.1.i386.rpmsblim-cmpi-devel-1.0.4-13a.el4_6.1.i386.rpmsblim-cmpi-fsvol-1.4.3-13a.el4_6.1.i386.rpmsblim-cmpi-fsvol-devel-1.4.3-13a.el4_6.1.i386.rpmsblim-cmpi-fsvol-test-1.4.3-13a.el4_6.1.i386.rpmsblim-cmpi-network-1.3.7-13a.el4_6.1.i386.rpmsblim-cmpi-network-devel-1.3.7-13a.el4_6.1.i386.rpmsblim-cmpi-network-test-1.3.7-13a.el4_6.1.i386.rpmsblim-cmpi-nfsv3-1.0.13-13a.el4_6.1.i386.rpmsblim-cmpi-nfsv3-test-1.0.13-13a.el4_6.1.i386.rpmsblim-cmpi-nfsv4-1.0.11-13a.el4_6.1.i386.rpmsblim-cmpi-nfsv4-test-1.0.11-13a.el4_6.1.i386.rpmsblim-cmpi-params-1.2.4-13a.el4_6.1.i386.rpmsblim-cmpi-params-test-1.2.4-13a.el4_6.1.i386.rpmsblim-cmpi-sysfs-1.1.8-13a.el4_6.1.i386.rpmsblim-cmpi-sysfs-test-1.1.8-13a.el4_6.1.i386.rpmsblim-cmpi-syslog-0.7.9-13a.el4_6.1.i386.rpmsblim-cmpi-syslog-test-0.7.9-13a.el4_6.1.i386.rpmsblim-gather-2.1.1-13a.el4_6.1.i386.rpmsblim-gather-devel-2.1.1-13a.el4_6.1.i386.rpmsblim-gather-provider-2.1.1-13a.el4_6.1.i386.rpmsblim-gather-test-2.1.1-13a.el4_6.1.i386.rpmsblim-testsuite-1.2.4-13a.el4_6.1.i386.rpmsblim-wbemcli-1.5.1-13a.el4_6.1.i386.rpm x86_64:sblim-cmpi-base-1.5.4-13a.el4_6.1.x86_64.rpmsblim-cmpi-base-devel-1.5.4-13a.el4_6.1.x86_64.rpmsblim-cmpi-base-test-1.5.4-13a.el4_6.1.x86_64.rpmsblim-cmpi-devel-1.0.4-13a.el4_6.1.x86_64.rpmsblim-cmpi-fsvol-1.4.3-13a.el4_6.1.x86_64.rpmsblim-cmpi-fsvol-devel-1.4.3-13a.el4_6.1.x86_64.rpmsblim-cmpi-fsvol-test-1.4.3-13a.el4_6.1.x86_64.rpmsblim-cmpi-network-1.3.7-13a.el4_6.1.x86_64.rpmsblim-cmpi-network-devel-1.3.7-13a.el4_6.1.x86_64.rpmsblim-cmpi-network-test-1.3.7-13a.el4_6.1.x86_64.rpmsblim-cmpi-nfsv3-1.0.13-13a.el4_6.1.x86_64.rpmsblim-cmpi-nfsv3-test-1.0.13-13a.el4_6.1.x86_64.rpmsblim-cmpi-nfsv4-1.0.11-13a.el4_6.1.x86_64.rpmsblim-cmpi-nfsv4-test-1.0.11-13a.el4_6.1.x86_64.rpmsblim-cmpi-params-1.2.4-13a.el4_6.1.x86_64.rpmsblim-cmpi-params-test-1.2.4-13a.el4_6.1.x86_64.rpmsblim-cmpi-sysfs-1.1.8-13a.el4_6.1.x86_64.rpmsblim-cmpi-sysfs-test-1.1.8-13a.el4_6.1.x86_64.rpmsblim-cmpi-syslog-0.7.9-13a.el4_6.1.x86_64.rpmsblim-cmpi-syslog-test-0.7.9-13a.el4_6.1.x86_64.rpmsblim-gather-2.1.1-13a.el4_6.1.x86_64.rpmsblim-gather-devel-2.1.1-13a.el4_6.1.x86_64.rpmsblim-gather-provider-2.1.1-13a.el4_6.1.x86_64.rpmsblim-gather-test-2.1.1-13a.el4_6.1.x86_64.rpmsblim-testsuite-1.2.4-13a.el4_6.1.x86_64.rpmsblim-wbemcli-1.5.1-13a.el4_6.1.x86_64.rpmSL 5.x SRPMS:sblim-1-31.el5_2.1.src.rpm i386:sblim-cim-client-1.3.3-31.el5_2.1.i386.rpmsblim-cim-client-javadoc-1-31.el5_2.1.i386.rpmsblim-cim-client-manual-1-31.el5_2.1.i386.rpmsblim-cmpi-base-1.5.5-31.el5_2.1.i386.rpmsblim-cmpi-base-devel-1.5.5-31.el5_2.1.i386.rpmsblim-cmpi-base-test-1.5.5-31.el5_2.1.i386.rpmsblim-cmpi-devel-1.0.4-31.el5_2.1.i386.rpmsblim-cmpi-dns-0.5.2-31.el5_2.1.i386.rpmsblim-cmpi-dns-devel-1-31.el5_2.1.i386.rpmsblim-cmpi-dns-test-1-31.el5_2.1.i386.rpmsblim-cmpi-fsvol-1.4.4-31.el5_2.1.i386.rpmsblim-cmpi-fsvol-devel-1.4.4-31.el5_2.1.i386.rpmsblim-cmpi-fsvol-test-1.4.4-31.el5_2.1.i386.rpmsblim-cmpi-network-1.3.8-31.el5_2.1.i386.rpmsblim-cmpi-network-devel-1.3.8-31.el5_2.1.i386.rpmsblim-cmpi-network-test-1.3.8-31.el5_2.1.i386.rpmsblim-cmpi-nfsv3-1.0.14-31.el5_2.1.i386.rpmsblim-cmpi-nfsv3-test-1.0.14-31.el5_2.1.i386.rpmsblim-cmpi-nfsv4-1.0.12-31.el5_2.1.i386.rpmsblim-cmpi-nfsv4-test-1.0.12-31.el5_2.1.i386.rpmsblim-cmpi-params-1.2.6-31.el5_2.1.i386.rpmsblim-cmpi-params-test-1.2.6-31.el5_2.1.i386.rpmsblim-cmpi-samba-0.5.2-31.el5_2.1.i386.rpmsblim-cmpi-samba-devel-1-31.el5_2.1.i386.rpmsblim-cmpi-samba-test-1-31.el5_2.1.i386.rpmsblim-cmpi-sysfs-1.1.9-31.el5_2.1.i386.rpmsblim-cmpi-sysfs-test-1.1.9-31.el5_2.1.i386.rpmsblim-cmpi-syslog-0.7.11-31.el5_2.1.i386.rpmsblim-cmpi-syslog-test-0.7.11-31.el5_2.1.i386.rpmsblim-gather-2.1.2-31.el5_2.1.i386.rpmsblim-gather-devel-2.1.2-31.el5_2.1.i386.rpmsblim-gather-provider-2.1.2-31.el5_2.1.i386.rpmsblim-gather-test-2.1.2-31.el5_2.1.i386.rpmsblim-testsuite-1.2.4-31.el5_2.1.i386.rpmsblim-tools-libra-0.2.3-31.el5_2.1.i386.rpmsblim-tools-libra-devel-0.2.3-31.el5_2.1.i386.rpmsblim-wbemcli-1.5.1-31.el5_2.1.i386.rpm x86_64:sblim-cim-client-1.3.3-31.el5_2.1.x86_64.rpmsblim-cim-client-javadoc-1-31.el5_2.1.x86_64.rpmsblim-cim-client-manual-1-31.el5_2.1.x86_64.rpmsblim-cmpi-base-1.5.5-31.el5_2.1.i386.rpmsblim-cmpi-base-1.5.5-31.el5_2.1.x86_64.rpmsblim-cmpi-base-devel-1.5.5-31.el5_2.1.i386.rpmsblim-cmpi-base-devel-1.5.5-31.el5_2.1.x86_64.rpmsblim-cmpi-base-test-1.5.5-31.el5_2.1.x86_64.rpmsblim-cmpi-devel-1.0.4-31.el5_2.1.i386.rpmsblim-cmpi-devel-1.0.4-31.el5_2.1.x86_64.rpmsblim-cmpi-dns-0.5.2-31.el5_2.1.i386.rpmsblim-cmpi-dns-0.5.2-31.el5_2.1.x86_64.rpmsblim-cmpi-dns-devel-1-31.el5_2.1.i386.rpmsblim-cmpi-dns-devel-1-31.el5_2.1.x86_64.rpmsblim-cmpi-dns-test-1-31.el5_2.1.x86_64.rpmsblim-cmpi-fsvol-1.4.4-31.el5_2.1.i386.rpmsblim-cmpi-fsvol-1.4.4-31.el5_2.1.x86_64.rpmsblim-cmpi-fsvol-devel-1.4.4-31.el5_2.1.i386.rpmsblim-cmpi-fsvol-devel-1.4.4-31.el5_2.1.x86_64.rpmsblim-cmpi-fsvol-test-1.4.4-31.el5_2.1.x86_64.rpmsblim-cmpi-network-1.3.8-31.el5_2.1.i386.rpmsblim-cmpi-network-1.3.8-31.el5_2.1.x86_64.rpmsblim-cmpi-network-devel-1.3.8-31.el5_2.1.i386.rpmsblim-cmpi-network-devel-1.3.8-31.el5_2.1.x86_64.rpmsblim-cmpi-network-test-1.3.8-31.el5_2.1.x86_64.rpmsblim-cmpi-nfsv3-1.0.14-31.el5_2.1.x86_64.rpmsblim-cmpi-nfsv3-test-1.0.14-31.el5_2.1.x86_64.rpmsblim-cmpi-nfsv4-1.0.12-31.el5_2.1.x86_64.rpmsblim-cmpi-nfsv4-test-1.0.12-31.el5_2.1.x86_64.rpmsblim-cmpi-params-1.2.6-31.el5_2.1.x86_64.rpmsblim-cmpi-params-test-1.2.6-31.el5_2.1.x86_64.rpmsblim-cmpi-samba-0.5.2-31.el5_2.1.i386.rpmsblim-cmpi-samba-0.5.2-31.el5_2.1.x86_64.rpmsblim-cmpi-samba-devel-1-31.el5_2.1.i386.rpmsblim-cmpi-samba-devel-1-31.el5_2.1.x86_64.rpmsblim-cmpi-samba-test-1-31.el5_2.1.x86_64.rpmsblim-cmpi-sysfs-1.1.9-31.el5_2.1.x86_64.rpmsblim-cmpi-sysfs-test-1.1.9-31.el5_2.1.x86_64.rpmsblim-cmpi-syslog-0.7.11-31.el5_2.1.x86_64.rpmsblim-cmpi-syslog-test-0.7.11-31.el5_2.1.x86_64.rpmsblim-gather-2.1.2-31.el5_2.1.i386.rpmsblim-gather-2.1.2-31.el5_2.1.x86_64.rpmsblim-gather-devel-2.1.2-31.el5_2.1.i386.rpmsblim-gather-devel-2.1.2-31.el5_2.1.x86_64.rpmsblim-gather-provider-2.1.2-31.el5_2.1.i386.rpmsblim-gather-provider-2.1.2-31.el5_2.1.x86_64.rpmsblim-gather-test-2.1.2-31.el5_2.1.x86_64.rpmsblim-testsuite-1.2.4-31.el5_2.1.x86_64.rpmsblim-tools-libra-0.2.3-31.el5_2.1.i386.rpmsblim-tools-libra-0.2.3-31.el5_2.1.x86_64.rpmsblim-tools-libra-devel-0.2.3-31.el5_2.1.i386.rpmsblim-tools-libra-devel-0.2.3-31.el5_2.1.x86_64.rpmsblim-wbemcli-1.5.1-31.el5_2.1.x86_64.rpm-Connie Sieh-Troy Dawson