lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <m1Ea6l6-000ogaC__45317.3127877109$1131651548$gmane$org@finlandia.Infodrom.North.DE>
Date: Thu, 10 Nov 2005 08:22:08 +0100 (CET)
From: joey@...odrom.org (Martin Schulze)
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 804-2] New kdelibs packages fix backup file information leak


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 804-2                     security@...ian.org
http://www.debian.org/security/                             Martin Schulze
November 10th, 2005                     http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : kdelibs
Vulnerability  : insecure permissions
Problem-Type   : local
Debian-specific: no
CVE ID         : CAN-2005-1920

Lennert Buytenhek discoverd that that patch to cure this information
leak was only included but not applied, hence, this update.  For
completeness we're copying the original advisory text:

   KDE developers have reported a vulnerability in the backup file
   handling of Kate and Kwrite.  The backup files are created with
   default permissions, even if the original file had more strict
   permissions set.  This could disclose information unintendedly.

For the stable distribution (sarge) this problem has been fixed in
version 3.3.2-6.3.

For the unstable distribution (sid) these problems have been fixed in
version 3.4.1-1.

We recommend that you upgrade your kate package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs_3.3.2-6.3.dsc
      Size/MD5 checksum:     1255 4cc793318c704d5f1cb868030981ff57
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs_3.3.2-6.3.diff.gz
      Size/MD5 checksum:   404229 e920360631a76024156c41be8b0d2d8f
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs_3.3.2.orig.tar.gz
      Size/MD5 checksum: 18250342 04f10ddfa8bf9e359f391012806edc04

  Architecture independent components:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-data_3.3.2-6.3_all.deb
      Size/MD5 checksum:  7094534 d789cc4683b501ad590346c23910be9e
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-doc_3.3.2-6.3_all.deb
      Size/MD5 checksum: 11535490 2dd64157788a25339fb308b66458dfc4
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs_3.3.2-6.3_all.deb
      Size/MD5 checksum:    27830 8d7466f5b7749c403f8391250ac758c2

  Alpha architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_alpha.deb
      Size/MD5 checksum:   995196 5f9857ea5b00a14e6cc354b9768fceb1
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_alpha.deb
      Size/MD5 checksum:  9283662 ed728107ba0e7de7540fa3dcc46b477a
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_alpha.deb
      Size/MD5 checksum:  1245858 65320a7b96a6be3dfbcca9c318e708e5

  AMD64 architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_amd64.deb
      Size/MD5 checksum:   923188 5a528318ef92909773877e2ee983a4d5
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_amd64.deb
      Size/MD5 checksum:  8514424 40d7c81a90bbea20c226dab00cd3342c
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_amd64.deb
      Size/MD5 checksum:  1241540 2811001f5f19093f5fe551199b91fe41

  ARM architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_arm.deb
      Size/MD5 checksum:   810844 39cab7f30f96450c373f32ca334967a9
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_arm.deb
      Size/MD5 checksum:  7595134 60546b0285bf8e894834870adaf13ecf
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_arm.deb
      Size/MD5 checksum:  1239196 1bdb9ee72fb2f76fee68d72861f496ca

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_i386.deb
      Size/MD5 checksum:   863314 15c9af4d49acd3c3a379e3182199242a
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_i386.deb
      Size/MD5 checksum:  8203078 fd52873f261beda4c1555322bdd87d9e
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_i386.deb
      Size/MD5 checksum:  1239110 bce6dd6e7e1d15a4c88f7d8eeff9506e

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_ia64.deb
      Size/MD5 checksum:  1148358 1a0c4d409176aa931f06bfaa8b341232
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_ia64.deb
      Size/MD5 checksum: 10773582 3ba603f7856d4261fbe02e4fafecbadf
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_ia64.deb
      Size/MD5 checksum:  1253394 d290b52e71350afbf918c21482eb4ebd

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_hppa.deb
      Size/MD5 checksum:   945060 a4f44240a21de6e464b170fe438a2f92
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_hppa.deb
      Size/MD5 checksum:  9306058 32dc28d4a85258230bf74440b7a463bc
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_hppa.deb
      Size/MD5 checksum:  1243456 2292057e1b77a5d9c519828f9e772cdc

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_m68k.deb
      Size/MD5 checksum:   837404 7ac4a4561a707881e55135da2cb0b9ca
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_m68k.deb
      Size/MD5 checksum:  7917390 f254d07d6338bf0f56d5f2446a0bd1d6
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_m68k.deb
      Size/MD5 checksum:  1237552 d36cf5bd1c6bba2026b7f9b1c5c964cb

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_mips.deb
      Size/MD5 checksum:   876114 2c246872e48005f205e45aa199f3d745
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_mips.deb
      Size/MD5 checksum:  7427108 896f75f3b75ae461ab2d91c194e5707d
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_mips.deb
      Size/MD5 checksum:  1238296 31fa531f08ff2f549d0fb3a47e92e279

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_mipsel.deb
      Size/MD5 checksum:   872144 f25c55dd931a5265b39399eceeee0878
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_mipsel.deb
      Size/MD5 checksum:  7298310 447c32f5c2b0f99b0e999a5b41e8c42d
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_mipsel.deb
      Size/MD5 checksum:  1238076 d99597a2b1d71aa3dd31ec99d1e7ae85

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_powerpc.deb
      Size/MD5 checksum:   903310 49855558e4435ff145561fe08baf2784
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_powerpc.deb
      Size/MD5 checksum:  7923194 c70cce93713c796edac94c60269b8986
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_powerpc.deb
      Size/MD5 checksum:  1242262 19ab356e9d7d75fc2ef2283e1cc734af

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_s390.deb
      Size/MD5 checksum:   892260 ab44f79cf338d47e4e8e0676a519eaf3
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_s390.deb
      Size/MD5 checksum:  8637096 20c0facec3660440c1442453ca141e5b
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_s390.deb
      Size/MD5 checksum:  1239604 f247f4e8a7f45ed40cea9bc5f4565b46

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs-bin_3.3.2-6.3_sparc.deb
      Size/MD5 checksum:   824478 b9439a32114155d605cb5a6198658a3c
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4_3.3.2-6.3_sparc.deb
      Size/MD5 checksum:  7746846 34dde44f7991164605c5f0c065265e46
    http://security.debian.org/pool/updates/main/k/kdelibs/kdelibs4-dev_3.3.2-6.3_sparc.deb
      Size/MD5 checksum:  1238884 33bd1f4555c64370c54fcd5f0ff82ff5


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@...ts.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDcvUfW5ql+IAeqTIRApL2AJ9Yi5FySnCOCdUMCY8iPA5GDPTmBwCgpLkL
4m/MhjacANSU/vxSYgkP2/w=
=nyU3
-----END PGP SIGNATURE-----



Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ