rPSA-2007-0014-2 libgtop
rPath Update Announcements announce-noreply at rpath.com
Wed Jan 24 15:38:41 EST 2007
Previous message: rPSA-2007-0015-1 libsoup
Next message: rPSA-2007-0019-1 gtk
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
--------------------------------------------------------------------------------
rPath Security Advisory: 2007-0014-2
Published: 2007-01-23
Updated:
2007-01-24 locale information restored
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
Local User Deterministic Denial of Service
Updated Versions:
libgtop=/conary.rpath.com at rpl:devel//1/2.12.0-1.3-1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0235
https://issues.rpath.com/browse/RPL-972
Description:
Previous versions of the libgtop package are vulnerable to an attack
in which a local user can at least cause programs that use libgtop
(such as gnome-system-monitor) to crash, and possibly to execute
arbitrary code as the user running the program.
24 January 2007 Update: The initial fix for this vulnerability
inadvertently removed locale information. This has been resolved.
Search for in Google by Dino
jueves, 25 de enero de 2007
libgtop (denial of service, code execution)
Publicado por http://hackinganddefense.blogspot.com/ Etiquetas: SEGURIDAD INFORMATICA en 9:33 p.m.
Suscribirse a:
Comentarios de la entrada (Atom)
No hay comentarios.:
Publicar un comentario