The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path. (CVE-2021-23239). . MGASA-2021-0042 - Updated sudo packages fix security vulnerabilities Publication date: 17 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0042.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-23239, CVE-2021-23240 The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path. (CVE-2021-23239). selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable. (CVE-2021-23240). References: - https://bugs.mageia.org/show_bug.cgi?id=28067 - https://www.openwall.com/lists/oss-security/2021/01/11/2 - - https://www.cve.org/CVERecord?id=CVE-2021-23239 - https://www.cve.org/CVERecord?id=CVE-2021-23240 SRPMS: - 7/core/sudo-1.9.5-1.mga7 . Fedora's FEDORA-2021-0055 upgrades glibc to mitigate risks posed by buffer overflow exploits that can lead to arbitrary code execution.. Mageia Sudo Fix, Symlink Attack Risks, Local Escalation Issues. . LinuxSecurity.com Team
New patch packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] patch (SSA:2015-047-01) New patch packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/patch-2.7.4-i486-1_slack14.1.txz: Upgraded. Patch no longer follows symbolic links to input and output files. This ensures that symbolic links created by git-style patches cannot cause patch to write outside the working directory. For more information, see: https://www.cve.org/CVERecord?id=CVE-2015-1196 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: Updated package for Slackware x86_64 13.0: Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: f887adfdfb23434dd3f37d3f49a9077d patch-2.7.4-i486-1_slack13.0.txz Slackware x86_64 13.0 package: 58455b6b9842e708d422038ab8fe7edb patch-2.7.4-x86_64-1_slack13.0.txz Slackware 13.1 package: fd369453096a7118ade75fe489ab17e9 patch-2.7.4-i486-1_slack13.1.txz Slackware x86_64 13.1 package: cc381cc22597f5553bf681dad3d343f0 patch-2.7.4-x86_64-1_slack13.1.txz Slackware13.37 package: acf0d74eee4378cb7d9118ff97825c6b patch-2.7.4-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 38281ce24307296474d00139783d5131 patch-2.7.4-x86_64-1_slack13.37.txz Slackware 14.0 package: 883366258723850e1c172833da20e9f3 patch-2.7.4-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 1ee2e9fa194f40682a551fb6b9bd83a7 patch-2.7.4-x86_64-1_slack14.0.txz Slackware 14.1 package: 7824fea560e2e0fe4510048e2bb3ce3b patch-2.7.4-i486-1_slack14.1.txz Slackware x86_64 14.1 package: e951553245144de113bc5950e6ebd7c6 patch-2.7.4-x86_64-1_slack14.1.txz Slackware -current package: 025d4917aca246e4bb81ec2c21cc7886 a/patch-2.7.4-i486-1.txz Slackware x86_64 -current package: 60940b74eaca8815b56b94de206a2e64 a/patch-2.7.4-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg patch-2.7.4-i486-1_slack14.1.txz +-----+ . Recent update bundles launched for Slackware address vulnerabilities and improve security measures.. Slackware Security Update, Patch Packages, Software Upgrade. . Severity: Important. LinuxSecurity.com Team
Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Texinfo: Insecure temporary file creation Date: October 05, 2005 Bugs: #106105 ID: 200510-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= Texinfo is the official documentation system created by the GNU project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/texinfo < 4.8-r1 > = 4.8-r1 Description ========== Frank Lichtenheld has discovered that the "sort_offline()" function in texindex insecurely creates temporary files with predictable filenames. Impact ===== A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When texindex is executed, this would result in the file being overwritten with the rights of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Texinfo users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/texinfo-4.8-r1" References ========= [ 1 ] CAN-2005-3011 https://www.cve.org/CVERecord?id=CVE-CAN-2005-3011 Availability =========== This GLSA andany updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200510-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
mtink is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running the utility. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: mtink: Insecure tempfile handling Date: November 09, 2004 Bugs: #70310 ID: 200411-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= mtink is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running the utility. Background ========= mtink is a status monitor and inkjet cartridge changer for some Epson printers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-print/mtink < 1.0.5 > = 1.0.5 Description ========== Tavis Ormandy from Gentoo Linux discovered that mtink uses insecure permissions on temporary files. Impact ===== A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When mtink is executed, this would result in the file being overwritten with the rights of the user running the utility, which could be the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All mtink users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-print/mtink-1.0.5" Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200411-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
A security problem has been discovered in getmail, a POP3 and APOP mail gatherer and forwarder. An attacker with a shell account on the victims host could utilise getmail to overwrite arbitrary files when it is running as root.. -------------------------------------------------------------------------- Debian Security Advisory DSA 553-1
These packages fix a security problem with remote clients giving specialNetBIOS names to the server.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: New Samba packages available for Red Hat Linux 5.2, 6.2, 7 and 7.1 Advisory ID: RHSA-2001:086-06 Issue date: 2001-06-23 Updated on: 2001-06-25 Product: Red Hat Linux Keywords: samba /tmp overwrite netbios log Cross references: Obsoletes: RHSA-2001:044 --------------------------------------------------------------------- 1. Topic: New Samba packages are available for Red Hat Linux 5.2, 6.2, 7 and 7.1. These packages fix a security problem with remote clients giving special NetBIOS names to the server. It is recommended that all Samba users upgrade to the fixed packages. Please note that the packages for Red Hat Linux 6.2 require an updated logrotate package. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386 3. Problem description: The Samba configuration used in Red Hat Linux logs operations into [remotenetbiosname].log. By sending an invalid netbiosname, Samba could be fooled to write its log in unintended and inappropriate locations. This can be especially dangerous if combined with a symlink created by a local user. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is alsoavailable via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 18df4fbdfa8594ea680595109964b409 5.2/en/os/SRPMS/samba-2.0.10-0.52.src.rpm cdf3e062dcaa6aa340e31e5cec5f0344 5.2/en/os/alpha/samba-2.0.10-0.52.alpha.rpm 604b9008fc1250d5c5a50d25988bc4b1 5.2/en/os/alpha/samba-client-2.0.10-0.52.alpha.rpm 9f65bdf5755a55a1c700067dc4b7c3c9 5.2/en/os/i386/samba-2.0.10-0.52.i386.rpm 79c327d3ef532cb64700a2ce0d5e66a0 5.2/en/os/i386/samba-client-2.0.10-0.52.i386.rpm a272092d5287bfe60671ac1e9492b1ec 5.2/en/os/sparc/samba-2.0.10-0.52.sparc.rpm 793af6719cbee2d0b15677e5a0943f1c 5.2/en/os/sparc/samba-client-2.0.10-0.52.sparc.rpm c6c163dc45803cce27d6c9ac4980b312 6.2/en/os/SRPMS/samba-2.0.10-0.62.src.rpm 346698143be2b970ab7b9a2daa4cb482 6.2/en/os/alpha/samba-2.0.10-0.62.alpha.rpm 66ec9df3884ea11dcc9aa65f9c00c0b9 6.2/en/os/alpha/samba-client-2.0.10-0.62.alpha.rpm fd65e0789cf5cb77b1cca71dd5d0cbe6 6.2/en/os/alpha/samba-common-2.0.10-0.62.alpha.rpm fe5cb3e1c2d85b609a23e8e6b9e18032 6.2/en/os/i386/samba-2.0.10-0.62.i386.rpm 592952ec4e6ebba775453790bff9f55c 6.2/en/os/i386/samba-client-2.0.10-0.62.i386.rpm 7aaab8758112c7eea1b9f5f82a618ccb 6.2/en/os/i386/samba-common-2.0.10-0.62.i386.rpm 0abcd0238a18311c26eba967a8256c5b 6.2/en/os/sparc/samba-2.0.10-0.62.sparc.rpm e21c51775e7af1aace2b76e0a36f126f 6.2/en/os/sparc/samba-client-2.0.10-0.62.sparc.rpm 513e63a960296b3cbdaac634f56413016.2/en/os/sparc/samba-common-2.0.10-0.62.sparc.rpm 1db7800a8973a157fe350c4073492a24 7.0/en/os/SRPMS/samba-2.0.10-0.7.src.rpm b23b1930ff12b4b5baed47c6f58ea204 7.0/en/os/alpha/samba-2.0.10-0.7.alpha.rpm d3dbd761b1b9aed27e2675bb8b0746df 7.0/en/os/alpha/samba-client-2.0.10-0.7.alpha.rpm 44d4aee596d2a775f2a79e873b93dd54 7.0/en/os/alpha/samba-common-2.0.10-0.7.alpha.rpm bab37137760e9955f8764a076c67c9ae 7.0/en/os/i386/samba-2.0.10-0.7.i386.rpm 826b1e504046b33ea5a979092fa54131 7.0/en/os/i386/samba-client-2.0.10-0.7.i386.rpm 3362bb219401f80c852614ec779d071e 7.0/en/os/i386/samba-common-2.0.10-0.7.i386.rpm c2d3bdaec859f09d31bcc14727e59918 7.1/en/os/SRPMS/samba-2.0.10-2.src.rpm 994f39fc465bb4dae3a94c2e0b608b4a 7.1/en/os/alpha/samba-2.0.10-2.alpha.rpm ca0e8961ccfa6f78ab6e9155b7068b20 7.1/en/os/alpha/samba-client-2.0.10-2.alpha.rpm ed3b2c72b04581f5345baf85044ff2e1 7.1/en/os/alpha/samba-common-2.0.10-2.alpha.rpm 59510f5d9f8bca09c35d5fa3fbb04553 7.1/en/os/alpha/samba-swat-2.0.10-2.alpha.rpm 988c5e7b554b659827897e52f8d13784 7.1/en/os/i386/samba-2.0.10-2.i386.rpm 9d5e0051d258f875236c3a317611f333 7.1/en/os/i386/samba-client-2.0.10-2.i386.rpm 5fe71e403bfd27da1de2325b734d28f8 7.1/en/os/i386/samba-common-2.0.10-2.i386.rpm dc667f249bd0c9024dcf751e513962f4 7.1/en/os/i386/samba-swat-2.0.10-2.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Strengthen your defense mechanisms by upgrading Samba elements to address precautions against unapproved entry threats in Red Hat systems, following this critical alert.. Red Hat Samba Update, Samba Symlink Risk, Remote Client Advisories. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.