Jump to content
Compatible Support Forums
Sign in to follow this  
news

[Security Announce] [ MDVSA-2009:343 ] acpid

Recommended Posts

This is a multi-part message in MIME format...

 

------------=_1261876015-24326-2503

 

 

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

 

_______________________________________________________________________

 

Mandriva Linux Security Advisory MDVSA-2009:343

http://www.mandriva.com/security/

_______________________________________________________________________

 

Package : acpid

Date : December 26, 2009

Affected: 2008.0, 2009.0, 2009.1, 2010.0, Enterprise Server 5.0

_______________________________________________________________________

 

Problem Description:

 

A vulnerability has been found and corrected in acpid:

 

acpid 1.0.4 sets an unrestrictive umask, which might allow local users

to leverage weak permissions on /var/log/acpid, and obtain sensitive

information by reading this file or cause a denial of service by

overwriting this file, a different vulnerability than CVE-2009-4033

(CVE-2009-4235).

 

Packages for 2008.0 are provided for Corporate Desktop 2008.0

customers.

 

This update provides a solution to this vulnerability.

_______________________________________________________________________

 

References:

 

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4235

_______________________________________________________________________

 

Updated Packages:

 

Mandriva Linux 2008.0:

7dd6b610563ca831eb83e967f13506b2 2008.0/i586/acpid-1.0.6-1.3mdv2008.0.i586.rpm

8297304a0403e39ea3efcba888ff724d 2008.0/SRPMS/acpid-1.0.6-1.3mdv2008.0.src.rpm

 

Mandriva Linux 2008.0/X86_64:

3392a3b0709127fa9bc109841effa00d 2008.0/x86_64/acpid-1.0.6-1.3mdv2008.0.x86_64.rpm

8297304a0403e39ea3efcba888ff724d 2008.0/SRPMS/acpid-1.0.6-1.3mdv2008.0.src.rpm

 

Mandriva Linux 2009.0:

59e8477a7814305dddf212c4d7e588a0 2009.0/i586/acpid-1.0.6-6.2mnb2.i586.rpm

f12e1341063ac477b76aa644ca5f27e6 2009.0/SRPMS/acpid-1.0.6-6.2mnb2.src.rpm

 

Mandriva Linux 2009.0/X86_64:

2ac48fd0d1cf20efff263a79a5ff2f00 2009.0/x86_64/acpid-1.0.6-6.2mnb2.x86_64.rpm

f12e1341063ac477b76aa644ca5f27e6 2009.0/SRPMS/acpid-1.0.6-6.2mnb2.src.rpm

 

Mandriva Linux 2009.1:

daab3097ead82987b8e2f407c4e3790f 2009.1/i586/acpid-1.0.8-1.2mnb2.i586.rpm

6a65518dc1bf7c5f7618daa1c1a12ca4 2009.1/SRPMS/acpid-1.0.8-1.2mnb2.src.rpm

 

Mandriva Linux 2009.1/X86_64:

e129cce48e8a0a044ab13eaf1397e38a 2009.1/x86_64/acpid-1.0.8-1.2mnb2.x86_64.rpm

6a65518dc1bf7c5f7618daa1c1a12ca4 2009.1/SRPMS/acpid-1.0.8-1.2mnb2.src.rpm

 

Mandriva Linux 2010.0:

5626a63068eaff19f47d44c68196304f 2010.0/i586/acpid-1.0.10-1.1mnb2.i586.rpm

3305e19f3053bbdeb023d05efc7756de 2010.0/SRPMS/acpid-1.0.10-1.1mnb2.src.rpm

 

Mandriva Linux 2010.0/X86_64:

549680e6a5dd1ca20f0986f85b2e48fc 2010.0/x86_64/acpid-1.0.10-1.1mnb2.x86_64.rpm

3305e19f3053bbdeb023d05efc7756de 2010.0/SRPMS/acpid-1.0.10-1.1mnb2.src.rpm

 

Mandriva Enterprise Server 5:

4c49de47912a7fd05ee89f2b346eaffc mes5/i586/acpid-1.0.6-6.2mnb2.i586.rpm

2b4ab4f965fbf8b19b45c67d7a447659 mes5/SRPMS/acpid-1.0.6-6.2mnb2.src.rpm

 

Mandriva Enterprise Server 5/X86_64:

9b391b5013a6d84aaac67588cec8d8c6 mes5/x86_64/acpid-1.0.6-6.2mnb2.x86_64.rpm

2b4ab4f965fbf8b19b45c67d7a447659 mes5/SRPMS/acpid-1.0.6-6.2mnb2.src.rpm

_______________________________________________________________________

 

To upgrade automatically use MandrivaUpdate or urpmi. The verification

of md5 checksums and GPG signatures is performed automatically for you.

 

All packages are signed by Mandriva for security. You can obtain the

GPG public key of the Mandriva Security Team by executing:

 

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 

You can view other update advisories for Mandriva Linux at:

 

http://www.mandriva.com/security/advisories

 

If you want to report vulnerabilities, please contact

 

security_(at)_mandriva.com

_______________________________________________________________________

 

Type Bits/KeyID Date User ID

pub 1024D/22458A98 2000-07-10 Mandriva Security Team

 

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.9 (GNU/Linux)

 

iD8DBQFLNmVjmqjQ0CJFipgRAnuiAJ9R8c1XwBlbqqRdlgQArBWBkUQ2oQCffYlO

AhSbAU+449T2xKriUgKqMnY=

=kcpK

-----END PGP SIGNATURE-----

 

 

------------=_1261876015-24326-2503

Content-Type: text/plain; name="message-footer.txt"

Content-Disposition: inline; filename="message-footer.txt"

Content-Transfer-Encoding: 8bit

 

To unsubscribe, send a email to sympa ( -at -) mandrivalinux.org

with this subject : unsubscribe security-announce

_______________________________________________________

Want to buy your Pack or Services from Mandriva?

Go to http://www.mandrivastore.com

Join the Club : http://www.mandrivaclub.com

_______________________________________________________

 

------------=_1261876015-24326-2503--

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×