6423425 2001-04-27 13:53 -0700 /66 rader/ Greg KH <greg@WIREX.COM> Sänt av: joel@lysator.liu.se Importerad: 2001-04-28 02:26 av Brevbäraren Extern mottagare: BUGTRAQ@SECURITYFOCUS.COM Externa svar till: greg@WIREX.COM Mottagare: Bugtraq (import) <16826> Ärende: Immunix OS Security update for gftp ------------------------------------------------------------ ----------------------------------------------------------------------- Immunix OS Security Advisory Packages updated: gftp Affected products: Immunix OS 6.2, 7.0-beta, and 7.0 Bugs Fixed: immunix/1578 Date: April 27, 2001 Advisory ID: IMNX-2001-70-017-01 Author: Greg Kroah-Hartman <greg@wirex.com> ----------------------------------------------------------------------- Description: Richard Johnson has found a format string problem in the version of gftp that ships with Immunix 6.2 and 7.0 (for more information, please see http://www.securityfocus.com/archive/82/177241 ) Normally, printf-style format bugs like this one would be stopped by FormatGuard, but FormatGuard is only effective at protecting applications that use the printf-like family of functions found in glibc. gftp uses string formatting functions found in GLib (the GTK+ library, *not* glibc) which bypass FormatGuard protection. The following packages fix this problem. Package names and locations: Precompiled binary package for Immunix 6.2 is available at: http://immunix.org/ImmunixOS/6.2/updates/RPMS/gftp-2.0.8-1_StackGuard.i386.rpm Source package for Immunix 6.2 is available at: http://immunix.org/ImmunixOS/6.2/updates/SRPMS/gftp-2.0.8-1_StackGuard.src.rpm Precompiled binary package for Immunix 7.0-beta and 7.0 is available at: http://immunix.org/ImmunixOS/7.0/updates/RPMS/gftp-2.0.8-1_imnx.i386.rpm Source package for Immunix 7.0-beta and 7.0 is available at: http://immunix.org/ImmunixOS/7.0/updates/SRPMS/gftp-2.0.8-1_imnx.src.rpm md5sums of the packages: 21ed7aec4ce92054a9d7b74144b677eb gftp-2.0.8-1_StackGuard.i386.rpm ec85dc5cf7f5a27387390039e152e78a gftp-2.0.8-1_StackGuard.src.rpm b9f4ee8b9b4bce6f8091040860dfd9da gftp-2.0.8-1_imnx.i386.rpm 282406a684ae7f546388a03c8491d3d8 gftp-2.0.8-1_imnx.src.rpm Online version of all Immunix 6.2 updates and advisories: http://immunix.org/ImmunixOS/6.2/updates/ Online version of all Immunix 7.0-beta updates and advisories: http://immunix.org/ImmunixOS/7.0-beta/updates/ Online version of all Immunix 7.0 updates and advisories: http://immunix.org/ImmunixOS/7.0/updates/ NOTE: Ibiblio is graciously mirroring our updates, so if the links above are slow, please try: ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/ or one of the many mirrors available at: http://www.ibiblio.org/pub/Linux/MIRRORS.html (6423425) /Greg KH <greg@WIREX.COM>/------(Ombruten) Bilaga (application/pgp-signature) i text 6423426 6423426 2001-04-27 13:53 -0700 /10 rader/ Greg KH <greg@WIREX.COM> Importerad: 2001-04-28 02:26 av Brevbäraren Extern mottagare: BUGTRAQ@SECURITYFOCUS.COM Externa svar till: greg@WIREX.COM Mottagare: Bugtraq (import) <16827> Bilaga (text/plain) till text 6423425 Ärende: Bilaga till: Immunix OS Security update for gftp ------------------------------------------------------------ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE66dxhAl5ylTeuKpURArTaAJ4s/IHrMSP0z1V3Xht7M8XXOKQ6ogCfezfr O7KK3I9TlH6UX+/hJVE/19Q= =7ScK -----END PGP SIGNATURE----- (6423426) /Greg KH <greg@WIREX.COM>/----------------