Updated dump packages that address two security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having low security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: dump security update Advisory ID: RHSA-2005:583-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:583.html Issue date: 2005-08-03 Updated on: 2005-08-03 Product: Red Hat Enterprise Linux CVE Names: CAN-2002-1914 - ---------------------------------------------------------------------1. Summary: Updated dump packages that address two security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having low security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: Dump examines files in a file system, determines which ones need to be backed up, and copies those files to a specified disk, tape, or other storage medium. A flaw was found with dump file locking. A malicious local user could manipulate the file lock in such a way as to prevent dump from running. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CAN-2002-1914 to this issue. Users of dump should upgrade to these erratum packages, which contain a patch to resolve this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive processthat will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 162903 - CAN-2002-1914 dump denial of service 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: a2105338ff2279973bcec74ea8dd96dd dump-0.4b25-1.72.2.src.rpm i386: b14ad2aef495fd52b2bfa8501147a86c dump-0.4b25-1.72.2.i386.rpm 1d658c6130d9b317456b56b6e21acd42 rmt-0.4b25-1.72.2.i386.rpm ia64: ace0b517d6b4d26fdfc40744368053cd dump-0.4b25-1.72.2.ia64.rpm f6ed788f99e81abdde859cbb4dabe1fb rmt-0.4b25-1.72.2.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: a2105338ff2279973bcec74ea8dd96dd dump-0.4b25-1.72.2.src.rpm ia64: ace0b517d6b4d26fdfc40744368053cd dump-0.4b25-1.72.2.ia64.rpm f6ed788f99e81abdde859cbb4dabe1fb rmt-0.4b25-1.72.2.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: a2105338ff2279973bcec74ea8dd96dd dump-0.4b25-1.72.2.src.rpm i386: b14ad2aef495fd52b2bfa8501147a86c dump-0.4b25-1.72.2.i386.rpm 1d658c6130d9b317456b56b6e21acd42 rmt-0.4b25-1.72.2.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: a2105338ff2279973bcec74ea8dd96dd dump-0.4b25-1.72.2.src.rpm i386: b14ad2aef495fd52b2bfa8501147a86c dump-0.4b25-1.72.2.i386.rpm 1d658c6130d9b317456b56b6e21acd42 rmt-0.4b25-1.72.2.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: http://marc.theaimsgroup.com/?l=bugtraq&m=102701096228027 https://www.cve.org/CVERecord?id=CAN-2002-1914 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Red Hat issued a minor severity patch for the dump software to mitigate local vulnerabilities. Ensure that the security update is implemented without delay.. Red Hat Enterprise, Dump Package, Low Severity, Security Fix. .Severity: Low. LinuxSecurity.com Team
Updated dump packages contain fixes for unintentional writes to target partition and other bugfixes. The updated dump also contains support for Extended Attributes/Access Control Lists.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-100 2005-02-02 ---------------------------------------------------------------------Product : Fedora Core 3 Name : dump Version : 0.4b39 Release : 1.FC3 Summary : Programs for backing up and restoring ext2/ext3 filesystems. Description : The dump package contains both dump and restore. Dump examines files in a filesystem, determines which ones need to be backed up, and copies those files to a specified disk, tape, or other storage medium. The restore command performs the inverse function of dump; it can restore a full backup of a filesystem. Subsequent incremental backups can then be layered on top of the full backup. Single files and directory subtrees may also be restored from full or partial backups. Install dump if you need a system for both backing up filesystems and restoring filesystems after backups. ---------------------------------------------------------------------Update Information: Updated dump packages contain fixes for unintentional writes to target partition and other bugfixes. The updated dump also contains support for Extended Attributes/Access Control Lists. ---------------------------------------------------------------------* Mon Jan 31 2005 Jindrich Novy 0.4b39-1.FC3 - Updated to dump-0.4b39. - Add patch for EA/ACL support. ---------------------------------------------------------------------This update can be downloaded from: 659d47ddef2e51b464ebbfd79aea8c4e SRPMS/dump-0.4b39-1.FC3.src.rpm f845ddadb8fc98963a5a9769069b5a8d x86_64/dump-0.4b39-1.FC3.x86_64.rpm d614d23c55414573d2a3350e760a1831 x86_64/rmt-0.4b39-1.FC3.x86_64.rpm df110c56be18f012714828aaa000cb13 x86_64/debug/dump-debuginfo-0.4b39-1.FC3.x86_64.rpm 75bce0eaa97ebb82d409af1e064d238a i386/dump-0.4b39-1.FC3.i386.rpm bd1b770bcc929c5c7169574024d5ee43 i386/rmt-0.4b39-1.FC3.i386.rpm ef9148270a30d0c6299892e9250e527c i386/debug/dump-debuginfo-0.4b39-1.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Updated dump packages contain fixes related to possible data corruption, unintentional writes to target partition and many other bugfixes. The updated dump also contains support for Extended Attributes/Access Control Lists.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-101 2005-02-02 ---------------------------------------------------------------------Product : Fedora Core 2 Name : dump Version : 0.4b39 Release : 1.FC2 Summary : Programs for backing up and restoring ext2/ext3 filesystems. Description : The dump package contains both dump and restore. Dump examines files in a filesystem, determines which ones need to be backed up, and copies those files to a specified disk, tape, or other storage medium. The restore command performs the inverse function of dump; it can restore a full backup of a filesystem. Subsequent incremental backups can then be layered on top of the full backup. Single files and directory subtrees may also be restored from full or partial backups. Install dump if you need a system for both backing up filesystems and restoring filesystems after backups. ---------------------------------------------------------------------Update Information: Updated dump packages contain fixes related to possible data corruption, unintentional writes to target partition and many other bugfixes. The updated dump also contains support for Extended Attributes/Access Control Lists. ---------------------------------------------------------------------* Mon Jan 31 2005 Jindrich Novy 0.4b39-1.FC2 - Updated to dump-0.4b39. - Add patch for EA/ACL support. ---------------------------------------------------------------------This update can be downloaded from: 9dc88be1d796ac53b5b17c134934b82b SRPMS/dump-0.4b39-1.FC2.src.rpm 28cfbd63ec6a3d22b364052c2576188f x86_64/dump-0.4b39-1.FC2.x86_64.rpm 703021f38ebbfef0cfd60ccf3db33b81 x86_64/rmt-0.4b39-1.FC2.x86_64.rpm 21580a17f855093128be7017d71dd691 x86_64/debug/dump-debuginfo-0.4b39-1.FC2.x86_64.rpm 4de7937aa2530c34920cb01f99366cf7 i386/dump-0.4b39-1.FC2.i386.rpm 3d6dd04e53f5e439b93fd59286650137 i386/rmt-0.4b39-1.FC2.i386.rpm 0f07deed6a88f438e896f512e5804cbb i386/debug/dump-debuginfo-0.4b39-1.FC2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
The version of dump that was distributed with Debian GNU/Linux 2.1 suffers from a problem with restoring symbolic links. . -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.