Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Slackware 14.1: SSA:2013-349-01 Low: Libodbc Remote Vulnerability Alert

slackware
Calendar Grey December 17, 2013
Dist Slackware Esm H88
Recent libiodbc updates for Slackware address a potential local security vulnerability that might enable unauthorized code execution.
New libiodbc packages are available for Slackware 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/libiodbc-3.52.8-i486-1_slack14.1.txz: Upgraded. This update fixes an rpath pointing to a location in /tmp that was found in two test programs (iodbctest and iodbctestw). This could have allowed a local attacker with write access to /tmp to add modified libraries (and execute arbitrary code) as any user running the test programs. Thanks to Christopher Oliver for the bug report. (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/libiodbc-3.52.8-i486-1_slack13.1.txz
Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/libiodbc-3.52.8-x86_64-1_slack13.1.txz
Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/libiodbc-3.52.8-i486-1_slack13.37.txz
Updated package for Slackware x86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/libiodbc-3.52.8-x86_64-1_slack13.37.txz
Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/libiodbc-3.52.8-i486-1_slack14.0.txz
Updated pa...

Read the Full Advisory

MD5 Signatures

Slackware 13.1 package: cd6968518bec2cbadd94eb9dd1fe24f9 libiodbc-3.52.8-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: cbe1095f613df181c3d019e5ea7d7927 libiodbc-3.52.8-x86_64-1_slack13.1.txz
Slackware 13.37 package: ea88a5b79f0708e5f25d17a8590416a7 libiodbc-3.52.8-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: 17ed09343f5f4b84ae14fbe728162d55 libiodbc-3.52.8-x86_64-1_slack13.37.txz
Slackware 14.0 package: 963680160b7b29673b53a82f319e92fa libiodbc-3.52.8-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: a14186bf5b9cf28a4724a54b6a2f2d81 libiodbc-3.52.8-x86_64-1_slack14.0.txz
Slackware 14.1 package: 6c056710fd7d7e81ef7c226f119ad540 libiodbc-3.52.8-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 3e4c5426c98e36a709f716735aa54962 libiodbc-3.52.8-x86_64-1_slack14.1.txz
Slackware -current package: ccbdabedb0d4a8517ef35025b4d0d6b6 l/libiodbc-3.52.8-i486-1.txz
Slackware x86_64 -current package: 0926927d530b956e31ab029525651de9 l/libiodbc-3.52.8-x86_64-1.txz

Severity
low
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg libiodbc-3.52.8-i486-1_slack14.1.txz

Related News

Your message here