![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Security Advisories (RSS) UNIX and Linux Security Advisories Via RSS News |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| USN-847-1: Devscripts vulnerability | iBot | Security Advisories (RSS) | 0 | 10-08-2009 06:00 PM |
| USN-608-1: KDE vulnerability | iBot | Security Advisories (RSS) | 0 | 05-06-2008 11:30 AM |
| S-067: Tk Vulnerability | iBot | Security Advisories (RSS) | 0 | 02-22-2008 05:20 PM |
| USN-579-1: Qt vulnerability | iBot | Security Advisories (RSS) | 0 | 02-21-2008 10:30 AM |
| S-121: VFS Vulnerability | iBot | Security Advisories (RSS) | 0 | 01-17-2008 07:10 PM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
|||||
|
USN-847-2: devscripts vulnerability
Referenced CVEs:
CVE-2009-2946 Description: =========================================================== Ubuntu Security Notice USN-847-2 October 09, 2009 devscripts vulnerability CVE-2009-2946 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: devscripts 2.9.10-0ubuntu0.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: USN-847-1 fixed vulnerabilities in devscripts. This update provides the corresponding updates for Ubuntu 6.06 LTS. Original advisory details: Raphael Geissert discovered that uscan, a part of devscripts, did not properly sanitize its input when processing pathnames. If uscan processed a crafted filename for a file on a remote server, an attacker could execute arbitrary code with the privileges of the user invoking the program. More... |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|