Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 6.06 LTS USN-847-2 Critical: Devscripts Code Execution Issue

Ubuntu Large Esm H500
USN-847-1 fixed vulnerabilities in devscripts. This update provides thecorresponding updates for Ubuntu 6.06 LTS.
==========================================================Ubuntu Security Notice USN-847-2           October 09, 2009
devscripts vulnerability
CVE-2009-2946
==========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
  devscripts                      2.9.10-0ubuntu0.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

USN-847-1 fixed vulnerabilities in devscripts. This update provides the
corresponding updates for Ubuntu 6.06 LTS.

Original advisory details:

 Raphael Geissert discovered that uscan, a part of devscripts, did not
 properly sanitize its input when processing pathnames. If uscan processed a
 crafted filename for a file on a remote server, an attacker could execute
 arbitrary code with the privileges of the user invoking the program.


Updated packages for Ubuntu 6.06 LTS:

  Source archives:

          Size/MD5:      715 46fa68657534c79a7742a7561d149764
          Size/MD5:   341732 84e4aacdd4495ad4df1e5ec2742bbc7e

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5:   296176 c136944ba913bad8591d288ad78ac856

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5:   295818 44d8620d6604b9ac51f52e4d4cd0c7dc

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5:   298350 a0bdd4a041737e983350b94cae6273d3

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5:   296218 613ed8459d8ac5ad221d71ec24c08464

Ubuntu 6.06 LTS USN-847-2 Critical: Devscripts Code Execution Issue

ubuntu
Calendar Grey October 9, 2009
Dist Ubuntu Esm H88
Ubuntu 6.06 LTS patch for devscripts resolves a severe vulnerability permitting arbitrary code execution. Significant security alert.
USN-847-1 fixed vulnerabilities in devscripts

Summary

Update Instructions

References

Severity
critical
Lowest
Low
Medium
High
Critical

devscripts vulnerability

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here