Updated due to new kernel scsi filtering.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-323 2004-09-30 --------------------------------------------------------------------- Product : Fedora Core 2 Name : cdrtools Version : 2.01.1 Release : 0.FC2.1 Summary : A collection of CD/DVD utilities. Description : cdrtools is a collection of CD/DVD utilities. --------------------------------------------------------------------- Update Information: Updated due to new kernel scsi filtering. --------------------------------------------------------------------- * Thu Sep 30 2004 Harald Hoyer - 8:2.01.1-0.FC2.1 - erratum for 2.6.8 kernel * Thu Sep 23 2004 Harald Hoyer - 8:2.01.1-3 - better globbing - readded O_EXCL opening for the direct device opening case, e.g. dev=/dev/cdrom - removed some debugging messages (bug 82089) * Tue Sep 14 2004 Harald Hoyer - 8:2.01.1-2 - fixed scsi-globbing * Tue Sep 14 2004 Harald Hoyer - 8:2.01.1-1 - final 2.01 version --------------------------------------------------------------------- This update can be downloaded from: 470275e0acbc271348045990fb18dc9b SRPMS/cdrtools-2.01.1-0.FC2.1.src.rpm ea35caf2c0ba664c0a3995c8dd042769 x86_64/cdrecord-2.01.1-0.FC2.1.x86_64.rpm e52d5b99c5e5c431abfceb91413b2b72 x86_64/cdrecord-devel-2.01.1-0.FC2.1.x86_64.rpm 4d9ed795e935925f69e7134f8100c23a x86_64/mkisofs-2.01.1-0.FC2.1.x86_64.rpm 0d8d425cafb028d7361ba4f98ac87985 x86_64/cdda2wav-2.01.1-0.FC2.1.x86_64.rpm 2180e190030f89a396f7530f8fd8cc84 x86_64/debug/cdrtools-debuginfo-2.01.1-0.FC2.1.x86_64.rpm 24a76389b1c0e6dbe0d9253d3de48a95 i386/cdrecord-2.01.1-0.FC2.1.i386.rpm a37d843fd38fc6db1fd0727ef8fd86d8 i386/cdrecord-devel-2.01.1-0.FC2.1.i386.rpm 028df80690bf6e8378594d1fe7ad4bcc i386/mkisofs-2.01.1-0.FC2.1.i386.rpm 5894d5f300e777ac1a8a8675bf2ba282 i386/cdda2wav-2.01.1-0.FC2.1.i386.rpm 0515f1d593b75511d94f23725a6b40bf i386/debug/cdrtools-debuginfo-2.01.1-0.FC2.1.i386.rpm This updatecan also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
Anyone who has manually suid /usr/bin/cdrecord should update to this version.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-298 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 2 Name : cdrtools Version : 2.01 Release : 0.a27.4.FC2.3 Summary : A collection of CD/DVD utilities. Description : cdrtools is a collection of CD/DVD utilities. --------------------------------------------------------------------- Update Information: Anyone who has manually suid /usr/bin/cdrecord should update to this version. CVE -CVE-2004-0806 --------------------------------------------------------------------- * Wed Sep 08 2004 Harald Hoyer - 8:2.01-0.a27.4.FC2.3 - added patch for CAN-2004-0806, if s.o. is so stupid to make cdrecord suid --------------------------------------------------------------------- This update can be downloaded from: 97a97d2384f9ab582736d985f6b8f302 SRPMS/cdrtools-2.01-0.a27.4.FC2.3.src.rpm 6dad4e7c175d300f9d7a0d2338139ca1 x86_64/cdrecord-2.01-0.a27.4.FC2.3.x86_64.rpm 3ca938e1c1c775bb774349e35dcca9c9 x86_64/cdrecord-devel-2.01-0.a27.4.FC2.3.x86_64.rpm fc4ceb93fb901065cad26be9d6e4b222 x86_64/mkisofs-2.01-0.a27.4.FC2.3.x86_64.rpm 6697f963ed06d27bbafc15dbc4a57e15 x86_64/cdda2wav-2.01-0.a27.4.FC2.3.x86_64.rpm 4426a57a0edcdd96cfcd5235dd97ec86 x86_64/debug/cdrtools-debuginfo-2.01-0.a27.4.FC2.3.x86_64.rpm df1786fde31756ea0e86cc6681a61036 i386/cdrecord-2.01-0.a27.4.FC2.3.i386.rpm 7290bd23cbdf9f2bd745a0f10e97588e i386/cdrecord-devel-2.01-0.a27.4.FC2.3.i386.rpm e211f8168b2871d28284a2a51cedfe1a i386/mkisofs-2.01-0.a27.4.FC2.3.i386.rpm 4ad7958b1c95aa4ad4d2309fc6c24bf8 i386/cdda2wav-2.01-0.a27.4.FC2.3.i386.rpm 6279fef62c5fbfa11a8550cd0731f798 i386/debug/cdrtools-debuginfo-2.01-0.a27.4.FC2.3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. --------------------------------------------------------------------- . Critical announcement for Fedora Core 2: cdrtools security patch addresses Denial of Service threats effectively.. Fedora Core 2,cdrtools,DoS threat,security advisory,software patch. . Severity: Critical. LinuxSecurity.com Team
Anyone who has manually suid /usr/bin/cdrecord should update to this version.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-297 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 1 Name : cdrtools Version : 2.01 Release : 0.a19.2.FC1.1 Summary : A collection of CD/DVD utilities. Description : cdrtools is a collection of CD/DVD utilities. --------------------------------------------------------------------- Update Information: Anyone who has manually suid /usr/bin/cdrecord should update to this version. CVE -CVE-2004-0806 --------------------------------------------------------------------- * Wed Sep 08 2004 Harald Hoyer - 8:2.01-0.a19.2.FC1.1 - added patch for CAN-2004-0806, if s.o. is so stupid to make cdrecord suid --------------------------------------------------------------------- This update can be downloaded from: 8c5baaa4f091b16370a2fc6e92684246 SRPMS/cdrtools-2.01-0.a19.2.FC1.1.src.rpm c3ce28f3c5b3190fd888db13f6a4de4c x86_64/cdrecord-2.01-0.a19.2.FC1.1.x86_64.rpm 32c300cf4f4bafd083782de090375c15 x86_64/cdrecord-devel-2.01-0.a19.2.FC1.1.x86_64.rpm e6a285ccdeba93bd15488ebb8ea29690 x86_64/mkisofs-2.01-0.a19.2.FC1.1.x86_64.rpm 86dde7afac3d91514876e876cf96c4e2 x86_64/cdda2wav-2.01-0.a19.2.FC1.1.x86_64.rpm c9cbb9577b4574f33357cb058eae6de4 x86_64/debug/cdrtools-debuginfo-2.01-0.a19.2.FC1.1.x86_64.rpm 02d85342deaca913ffb55b97bba42e10 i386/cdrecord-2.01-0.a19.2.FC1.1.i386.rpm 2c2ecccb5de0d111e1d23bc40d70cfdc i386/cdrecord-devel-2.01-0.a19.2.FC1.1.i386.rpm 969a9959cb2dac9295cb6a1fd6c48a49 i386/mkisofs-2.01-0.a19.2.FC1.1.i386.rpm 3df104a4966c5c075a8acbdc7248d362 i386/cdda2wav-2.01-0.a19.2.FC1.1.i386.rpm 1101f36dc1b269f940805eea77fd4da8 i386/debug/cdrtools-debuginfo-2.01-0.a19.2.FC1.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. --------------------------------------------------------------------- . Crucial update for Fedora Core 1 addresses cdrtools security flaw. Protect your system's integrity by executing the newest update without delay.. cdrtools update,Fedora security,cdrtools suid fix,Fedora Core 1. . Severity: Important. LinuxSecurity.com Team
Incorrect link fixed. A vulnerability in cdrecord that could lead to a root compromise was discovered. cdrecord is not installed suid by default in Gentoo.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-06.1 - - --------------------------------------------------------------------- PACKAGE : cdrtools SUMMARY : privelige escalation DATE : 2003-05-18 12:18 UTC EXPLOIT : local VERSIONS AFFECTED : =cdrtools-2.01_alpha14, =cdrtools-1.11.33-r1, =cdrtools-1.11.39-r1 CVE : CAN-2003-0289 - - --------------------------------------------------------------------- Last advisory had the wrong url to the advisory. -- Cdrecord isn't installed setuid root by default in Gentoo. Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105285564307225&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running app-cdr/cdrtools upgrade to one of the following versions: for users running xcdroast: cdrtools-1.11.33-r1 for sparc users: cdrtools-1.11.39-r1 for everyone else: cdrtools-2.01_alpha14 emerge sync emerge \=app-cdr/ emerge clean - - ---------------------------------------------------------------------
A vulnerability in cdrecord that could lead to a root compromise was discovered. cdrecord is not installed suid by default in Gentoo.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-06 - - --------------------------------------------------------------------- PACKAGE : cdrtools SUMMARY : privelige escalation DATE : 2003-05-17 14:07 UTC EXPLOIT : local VERSIONS AFFECTED : =cdrtools-2.01_alpha14, =cdrtools-1.11.33-r1, =cdrtools-1.11.39-r1 CVE : CAN-2003-0289 - - --------------------------------------------------------------------- Cdrecord isn't installed setuid root by default in Gentoo. Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105285351304781&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running app-cdr/cdrtools upgrade to one of the following versions: for users running xcdroast: cdrtools-1.11.33-r1 for sparc users: cdrtools-1.11.39-r1 for everyone else: cdrtools-2.01_alpha14 emerge sync emerge \=app-cdr/ emerge clean - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.