An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. openSUSE Security Update: ppc64-diag: fix for tmp races and information disclosure ______________________________________________________________________________ Announcement ID: openSUSE-SU-2014:0953-2 Rating: important References: #882667 Cross-References: CVE-2014-4038 CVE-2014-4039 Affected Products: openSUSE 12.3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: ppc64-diag was updated to fix tmp race issues (CVE-2014-4038) and a file disclosure problem in snapshot tarball generation (CVE-2014-4039). Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 12.3: zypper in -t patch openSUSE-2014- To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 12.3 (ppc ppc64): ppc64-diag-2.6.0-2.4.1 ppc64-diag-debuginfo-2.6.0-2.4.1 ppc64-diag-debugsource-2.6.0-2.4.1 References: https://www.suse.com/security/cve/CVE-2014-4038.html https://www.suse.com/security/cve/CVE-2014-4039.html . The update for ppc64-diag resolves temporary race conditions and prevents potential information exposure vulnerabilities affecting openSUSE 12.3.. ppc64-diag, tmp race issues, information disclosure, openSUSE security, security update. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. openSUSE Security Update: ppc64-diag: fix for tmp races and information disclosure ______________________________________________________________________________ Announcement ID: openSUSE-SU-2014:0953-1 Rating: important References: #882667 Cross-References: CVE-2014-4038 CVE-2014-4039 Affected Products: openSUSE 13.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: ppc64-diag was updated to fix tmp race issues (CVE-2014-4038) and a file disclosure problem in snapshot tarball generation (CVE-2014-4039). Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.1: zypper in -t patch openSUSE-2014- To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.1 (ppc ppc64): ppc64-diag-2.6.1-2.4.1 ppc64-diag-debuginfo-2.6.1-2.4.1 ppc64-diag-debugsource-2.6.1-2.4.1 References: https://www.suse.com/security/cve/CVE-2014-4038.html https://www.suse.com/security/cve/CVE-2014-4039.html . A critical update for openSUSE addresses race conditions in tmp directories and prevents potential information leaks associated with the ppc64-diag utility.. ppc64-diag update, openSUSE security, tmp race fix, information disclosure. . Severity: Important. LinuxSecurity.com Team
By exploiting these vulnerabilities,local users could overwrite any file in the system.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: New samba packages available to fix /tmp races Advisory ID: RHSA-2001:044-08 Issue date: 2001-04-05 Updated on: 2001-05-14 Product: Red Hat Linux Keywords: samba /tmp overwrite Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: New samba packages are available; these packages fix /tmp races in smbclient and the printing code. By exploiting these vulnerabilities, local users could overwrite any file in the system. It is recommended that all samba users upgrade to the fixed packages. Please note that the packages for Red Hat Linux 6.2 require an updated logrotate package. Note: these packages include the security patch from Samba-2.0.9. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - i386 3. Problem description: The printing code in smbd uses predictable filenames in /tmp, and passes them as an output file to system(); a user could create a symbolic link in /tmp and then overwrite any file on the system; later on chmod(0666) is called on the file, leading to even more problems. The smbclient 'more' and 'mput' commands also used /tmp files insecurely; this is less of a risk in that these are not normally run as root. Thanks go to Marcus Meissner (
Get the latest Linux and open source security news straight to your inbox.