From secure@conectiva.com.br Fri Feb 6 02:24:14 2004 From: Conectiva Updates To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org Date: Thu, 5 Feb 2004 18:12:40 -0200 Subject: [CLA-2004:811] Conectiva Security Announcement - libtool -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -------------------------------------------------------------------------- PACKAGE : libtool SUMMARY : Insecure handling of temporary files DATE : 2004-02-05 18:11:00 ID : CLA-2004:811 RELEVANT RELEASES : 8, 9 - ------------------------------------------------------------------------- DESCRIPTION GNU libtool consists of a set of shell scripts used to build shared libraries. Joseph S. Myers and Stefan Nordhausen independently found[1,2] a vulnerability[3] in the way the ltmain.sh script (which is part of the libtool package) creates temporary directories for its use. A local attacker could exploit this vulnerability to change/delete arbitrary files in the system on behalf of the user who is calling the script. The vulnerability has been fixed in the 1.5.2 version of libtool. This update keeps the original versions distributed with Conectiva Linux, fixing the vulnerability by using mktemp to securely create the directories. SOLUTION All developers using libtool should upgrade. REFERENCES 1.http://www.securityfocus.com/archive/1/352333 2.http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&list=405 3.http://www.securityfocus.com/bid/9530 UPDATED PACKAGES ftp://atualizacoes.conectiva.com.br/8/RPMS/libtool-1.4.2-4U80_2cl.i386.rpm ftp://atualizacoes.conectiva.com.br/8/SRPMS/libtool-1.4.2-4U80_2cl.src.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/libtool-1.4.3-21152U90_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/SRPMS/libtool-1.4.3-21152U90_1cl.src.rpm ADDITIONAL INSTRUCTIONS The apt tool can be used to perform RPM packages upgrades: - run: apt-get update - after that, execute: apt-get upgrade Detailed instructions reagarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en - ------------------------------------------------------------------------- All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en - ------------------------------------------------------------------------- All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en - ------------------------------------------------------------------------- Copyright (c) 2004 Conectiva Inc. http://www.conectiva.com - ------------------------------------------------------------------------- subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFAIqO342jd0JmAcZARArR7AJ9GvIg/XwNco0Nm35czt4Jo+DT7jACgwTyE lN5/U6mHObEGxXNZ89ij2kc= =ZV9T -----END PGP SIGNATURE-----