New kdebase packages are available for Slackware 10.0, 10.1, and -current to fix a security issue with the kcheckpass program. Earlier versions of Slackware are not affected. A flaw in the way the program creates lockfiles could allow a local attacker to gain root privileges. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] kcheckpass in kdebase (SSA:2005-251-01) New kdebase packages are available for Slackware 10.0, 10.1, and -current to fix a security issue with the kcheckpass program. Earlier versions of Slackware are not affected. A flaw in the way the program creates lockfiles could allow a local attacker to gain root privileges. For more details about the issue, see: https://kde.org/info/security/advisory-20050905-1.txt https://www.cve.org/CVERecord?id=CAN-2005-2494 Here are the details from the Slackware 10.1 ChangeLog: +--------------------------+ patches/packages/kdebase-3.3.2-i486-2.tgz: Patched a security bug in kcheckpass that could allow a local user to gain root privileges. For more information, see: https://kde.org/info/security/advisory-20050905-1.txt https://www.cve.org/CVERecord?id=CAN-2005-2494 (* Security fix *) +--------------------------+ Where to find the new package: +----------------------------+ Updated package for Slackware 10.0: Updated package for Slackware 10.1: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 10.0 package: 89cbad3536bbfba273b2ae77a097ce89 kdebase-3.2.3-i486-3.tgz Slackware 10.1 package: 6d2d8c96dc1f5b209b5eb35425ae7952 kdebase-3.3.2-i486-2.tgz Slackware -current package: 8b7066a01eb25a8b846d2ac9a5de85e2 kdebase-3.4.2-i486-2.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg kdebase-3.3.2-i486-2.tgz +-----+ . Notice for Slackware kdebase resolves kcheckpass lockfile vulnerability enabling local root escalation. Implement the fix immediately!. kdebase, Slackware security, kcheckpass update, local privilege escalation.. Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.