| [Security Announce] [ MDVSA-2008:074 ] - Updated audacity package fixes insecure temporary directory creation |
|
|
|
| Écrit par Administrator |
| Vendredi, 21 Mars 2008 09:55 |
|
 _______________________________________________________________________   Mandriva Linux Security Advisory                        MDVSA-2008:074  http://www.mandriva.com/security/  _______________________________________________________________________   Package : audacity  Date   : March 20, 2008  Affected: 2007.1, 2008.0, Corporate 3.0  _______________________________________________________________________   Problem Description:   Audacity creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. This issue can also be leveraged to delete arbitrary files or directories via a symlink attack.   The updated package fixes the issue.  _______________________________________________________________________  References:   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6061  _______________________________________________________________________ Updated Packages:   Mandriva Linux 2007.1:  5ebb4356f5e9410fb34fd13b1d9f52e0 2007.1/i586/audacity-1.3.2-4.1mdv2007.1.i586.rpm  b209fd344cd78af953a44187221e24b4 2007.1/SRPMS/audacity-1.3.2-4.1mdv2007.1.src.rpm  Mandriva Linux 2007.1/X86_64:  495b67476845f9831c5aa509cb4fed56 2007.1/x86_64/audacity-1.3.2-4.1mdv2007.1.x86_64.rpm  b209fd344cd78af953a44187221e24b4 2007.1/SRPMS/audacity-1.3.2-4.1mdv2007.1.src.rpm  Mandriva Linux 2008.0:  ba5c283112363eb7a5ba759ee19db460 2008.0/i586/audacity-1.3.3-1.1mdv2008.0.i586.rpm  07e566b52f9c14b4fb457d317ace5132 2008.0/SRPMS/audacity-1.3.3-1.1mdv2008.0.src.rpm  Mandriva Linux 2008.0/X86_64:  b6e400b8db075cb58e1a3d739fbcd45c 2008.0/x86_64/audacity-1.3.3-1.1mdv2008.0.x86_64.rpm  07e566b52f9c14b4fb457d317ace5132 2008.0/SRPMS/audacity-1.3.3-1.1mdv2008.0.src.rpm  Corporate 3.0:  8b6718bc8dfa06a369b56d4b54506c82 corporate/3.0/i586/audacity-1.2.0-1.1.C30mdk.i586.rpm  646559674bbb1a57cb867b8122a1794d corporate/3.0/SRPMS/audacity-1.2.0-1.1.C30mdk.src.rpm  Corporate 3.0/X86_64:  de7a02ceda34724803ac961ba153523b corporate/3.0/x86_64/audacity-1.2.0-1.1.C30mdk.x86_64.rpm  646559674bbb1a57cb867b8122a1794d corporate/3.0/SRPMS/audacity-1.2.0-1.1.C30mdk.src.rpm  _______________________________________________________________________  To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.  All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98  You can view other update advisories for Mandriva Linux at:  http://www.mandriva.com/security/advisories  If you want to report vulnerabilities, please contact  security_(at)_mandriva.com  _______________________________________________________________________ |



























































