[Full-Disclosure] GLSA: atari800 (200309-07)

From: Daniel Ahlberg (alizat_private)
Date: Tue Sep 02 2003 - 07:03:13 PDT

  • Next message: - o s g o -: "[Full-Disclosure] Re: atari800 (200309-07)"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200309-07
    - - - ---------------------------------------------------------------------
    
              PACKAGE : atari800
              SUMMARY : buffer overflow
                 DATE : 2003-09-02 14:03 UTC
              EXPLOIT : local
    VERSIONS AFFECTED : <atari800-1.3.0-r1
        FIXED VERSION : >=atari800-1.3.0-r1
                  CVE : CAN-2003-0630
    
    - - - ---------------------------------------------------------------------
    
    atar800 contains a buffer overflow which could be used by an attacker
    to gain root privileges. Altough the atari800 package in Gentoo does not 
    install any files suid root we encourage our users to upgrade.
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    app-emulation/atari800 upgrade to atari800-1.3.0-r1 as follows:
    
    emerge sync
    emerge atari800
    emerge clean
    
    - - - ---------------------------------------------------------------------
    alizat_private - GnuPG key is available at http://dev.gentoo.org/~aliz
    - - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)
    
    iD8DBQE/VKMhfT7nyhUpoZMRAmR0AJ9PopV3XZygpzI4/GoxVTJevEZr4wCfSeRZ
    HdaV5oJSNjQ7ahlvDHe2ZKo=
    =cktf
    -----END PGP SIGNATURE-----
    
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Tue Sep 02 2003 - 07:31:06 PDT