openSUSE Security Announce
Threads by month
- ----- 2024 -----
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
- 2 participants
- 10532 discussions
-----BEGIN PGP SIGNED MESSAGE-----
Dear suse-security-announce subscriber,
With the release of the SuSE Linux 8.0 i386 ftp version, we announce
that the SuSE Linux 6.4 distribution will be discontinued.
The high quality standard at SuSE and new features necessary for ftp support
required extensive testing of the SuSE Linux 8.0 i386 ftp version. We regret
the delay that was the result.
Vulnerabilities found after Monday, June 17 2002, will not receive a fix
for SuSE Linux 6.4 any more. After two years of successful use, SuSE Linux
6.4 will free resources for the newly released products. By consequence,
the 6.4 distributions directories on the ftp server have been moved to the
discontinued directory structure; the 6.4 directories in the update trees
will follow near the end of the month, soon after all update packages have
been published.
SuSE puts much effort into adding security improvements (patches) to the
software instead of publishing a new version; the same program with a fix
for a specific problem promises to work just as reliable as the original
version from the distribution, whereas new versions introduce new
functionality which changes the behaviour.
In some cases however, especially if the security leak is based on
problematic design decisions or when the fix(es) are fairly large, the
only reasonable fix for a security problem is to update to a newer version
of the software. These newer versions tend to become incompatible with our
older distribution releases because of missing features in the operating
system environment. This forces us to focus on the distributions of a
newer release date.
As usual, SuSE will continue to provide update packages for the remaining
distributions
SuSE-7.0
SuSE-7.1
SuSE-7.2
SuSE-7.3
and
SuSE-8.0
for a two-year period after the release of the respective distribution.
Our SLES (SuSE Linux Enterprise Server) products and the patches support
for them are not affected by this announcement.
If you have any questions regarding this announcement, please send email
to security(a)suse.de (primary security contact).
Regards,
Roman Drahtmüller,
SuSE Security.
- --
- -
| Roman Drahtmüller <draht(a)suse.de> // "You don't need eyes to see, |
SuSE Linux AG - Security Phone: // you need vision!"
| Nürnberg, Germany +49-911-740530 // Maxi Jazz, Faithless |
- -
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPQUf/Hey5gA9JdPZAQETtgf+MElVghYqHZd8up8rbID3+Ovw0a8U+kjQ
WZpmnD4wWOycNyTBHeh0ial8y66GWL3LeTzLd6U3n3tpU8cklb6js5nMlUHOI85L
y1M9qV/L332GfChcDmuEkPSvmrNyISEsqTHer6u/3HdXsT6epEJLu9Y0lr8Kihg6
INU+ww2HBtldlfjszEACLJdHzHo9vbMI5yg8t/d52/5b8h4zB9lsOawq1SNQpUpi
JiYT1S3u6K9dydGdXMPgBt2N9QWKJc2sgvg80NeKumvA6ZHuGpwBUybmHSnqjY+T
ScegNfAd3w5nYdigzZowZNRCNV5BMTnEmvwlDgBFgBuwscUuFMMHrQ==
=nZp1
-----END PGP SIGNATURE-----
1
0
06 Jun '02
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: bind9, bind9-beta
Announcement-ID: SuSE-SA:2002:021
Date: Thursday, Jun 6th, 02:00 MEST 2002
Affected products: 7.0, 7.1, 7.2, 7.3, 8.0
Vulnerability Type: remote denial of service attack
Severity (1-10): 4
SuSE default package: no
Other affected systems: systems running ISC bind9
Content of this advisory:
1) security vulnerability resolved: bind9 NAPTR bug
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
There is a bug in the BIND9 name server that is triggered when
processing certain types of DNS replies. When this happens an
assertion will fail, and named will log a message to the system log
before exiting. This means a remote attacker can easily shut down
the name server process.
This bug has been fixed using a patch provided by ISC via CERT.
Since there is no workaround to this problem, we recommend that
all users of bind9 update to the new packages.
Note that on SuSE 7.1 and later, it is not sufficient to update the
bind9 package itself; the vulnerability occurs in a shared library
included in the bind9-utils package.
Please also note that SuSE Linux after and including 7.3 contain two
different bind9 packages: One called bind9 with its subpackages,
and one called bind9-beta, also with subpackages. Use the command
rpm -qa|grep bind9
to find out which version of bind9 is installed on your system.
We recommend to run a non-beta version of bind9 on production systems.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind9-9.1.3-197.i386.rpm
977b9534745eb690505717a3571b30aa
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind9-devel-9.1.3-197.i386.r…
171da9e793bc862c9640ab8612bc03ec
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind9-utils-9.1.3-197.i386.r…
893939f98a05c93ad4608940bffff1ed
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind9-beta-9.2.0rc8-184.i386…
dec3cf6f050b0ce407042512cbbdaed4
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind9-beta-devel-9.2.0rc8-18…
fa030c5ca298e286cdcc4a9d0247c4e9
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind9-beta-utils-9.2.0rc8-18…
bc30bb07a1af0890964d49d0dc1c09f7
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/bind9-9.1.3-197.src.rpm
4b6995d7800dbe58d034550952c7624d
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/bind9-beta-9.2.0rc8-184.src…
fd1d33294a5b725ddd27dd70499ea91a
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/bind9-9.1.3-197.i386.rpm
09ce8bea81bcde8b1edd519d6410d439
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/bind9-devel-9.1.3-197.i386.r…
4987bc577cc9e5aec835748d18d3eac3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/bind9-utils-9.1.3-197.i386.r…
cab272685835e7699df066c0c9ebb258
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n3/bind9-beta-9.2.0rc3-15.i386.…
61169765b31e9ff3b161ea186cbdc0a0
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n3/bind9-beta-devel-9.2.0rc3-15…
7fa8cddcd49230b828451d2cacd74c92
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n3/bind9-beta-utils-9.2.0rc3-15…
62e579cdb4cd2bcb681f4bf54971a468
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/bind9-9.1.3-197.src.rpm
91ae3abc71fd781aec55b1c8ac2e21df
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/bind9-beta-9.2.0rc3-15.src.…
c8c59132967bbfc9a7fcf5f297638b00
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/bind9-9.1.2-30.i386.rpm
f4502e355f2722ec96733b27608d4f05
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/bind9-devel-9.1.2-30.i386.rpm
9cb7b5e0bccdd860d82b04a2e9bcf7b6
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/bind9-utils-9.1.2-30.i386.rpm
c9b10ae881883f0c922ec533e8183348
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/bind9-9.1.2-30.src.rpm
0d0242b905597272d9d2c0e0604850b9
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n2/bind9-9.1.0-14.i386.rpm
c895497e974942d04ef21b006e3675dd
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/bind9-9.1.0-14.src.rpm
eb3f0c06b7f48b22f6b0643308fa5416
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n1/bind9-9.1.0-14.i386.rpm
9641ca6ea855bb6ab2dbdf4120b14f4f
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/bind9-9.1.0-14.src.rpm
5c5068d75e9f82f51eaeb7a7cdebf4fe
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n2/bind9-9.1.3-99.sparc.rpm
9048e99a7f475bae32e9802a3e7b746c
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n2/bind9-devel-9.1.3-99.sparc.…
2ae6a105e6a121f5e196d6e50dcad3d5
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n2/bind9-utils-9.1.3-99.sparc.…
30fc3686362432b39eb9392f3216721e
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n3/bind9-beta-9.2.0rc3-14.spar…
3b464d9990d38e2f10b1e4fc099296b2
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n3/bind9-beta-devel-9.2.0rc3-1…
68a48ee60aeca3fca9b3c5b412a57eeb
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n3/bind9-beta-utils-9.2.0rc3-1…
89d0c48b30cea49ed45b3e9a85a6e8ea
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/bind9-9.1.3-99.src.rpm
b12c98e80e665c7ca1535cfdf0dbd714
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/bind9-beta-9.2.0rc3-14.src…
3f006049ac4a34c5e530383a50d44d13
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/n2/bind9-9.1.0-12.sparc.rpm
a22c5ab2946256353a6f1c1e2ee4ea97
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/zq1/bind9-9.1.0-12.src.rpm
0e62be9cdfa61ffaf4215b78dcfc2102
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/n1/bind9-9.1.0-11.sparc.rpm
224b2fea9810b3eb13c5b0fe89780edf
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/zq1/bind9-9.1.0-11.src.rpm
5cf703f04e01cae221246d7858f7a6b2
AXP Alpha Platform:
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n2/bind9-9.1.0-24.alpha.rpm
2f6d7b54ea846c2ea6377595fb86c101
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.1/zq1/bind9-9.1.0-24.src.rpm
21f13be34c6ea02c94719642828ae476
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n1/bind9-9.1.0-23.alpha.rpm
257753fbe9d5451cb86787a4f6154adb
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/bind9-9.1.0-23.src.rpm
57d117c32156e86cc288dc3ba7a61285
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/bind9-9.1.3-157.ppc.rpm
8cb5ba31882a19056f33d46ff64a06a0
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/bind9-devel-9.1.3-157.ppc.rpm
d04a7880522682467aa60490b0d042cb
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/bind9-utils-9.1.3-157.ppc.rpm
cd7241514ac72d0434c7e306df1b1420
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n3/bind9-beta-9.2.0rc3-24.ppc.rpm
e4b9a45857d995f64c588b4f143414c7
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n3/bind9-beta-devel-9.2.0rc3-24.…
b26452e3f1d871e5e4285fe587d57d5f
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n3/bind9-beta-utils-9.2.0rc3-24.…
efe525d315ae29843cff2e08f7340dd3
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/bind9-9.1.3-157.src.rpm
5f14e227b6dcb9f9728a25c3d8bcee91
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/bind9-beta-9.2.0rc3-24.src.r…
75f484db344dd55914a4800e38343fe8
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n2/bind9-9.1.0-16.ppc.rpm
96c9d2456332b4c29017adb06e5a51dc
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/bind9-9.1.0-16.src.rpm
df27c86f3857bcab346f917453512cfe
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n1/bind9-9.1.0-16.ppc.rpm
2f25bf268393ac843f082b265425e12a
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/bind9-9.1.0-16.src.rpm
6f7c98003d5e8c01b8900f02fb7b62bb
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- slurp - in a posting to bugtraq, a vulnerability in an NNTP news client
named slurp was reported. slurp should not be confused with "slurpd",
which is part of the openldap/openldap2 package. SuSE does not ship
slurp, the news client, and is therefore not vulnerable.
- ghostscript - RedHat Security released an announcement concerning a
problem in ghostscript, which could be exploited to gain the privileges
of the print server user. We are investigating whether SuSE Linux is
affected.
- kernel netfilter update - we are in the process of preparing a kernel
update that will include a security fix for a minor netfilter bug.
- fetchmail - we are in the process of releasing a security update for
fetchmail that corrects a vulnerability that could be exploited by
hostile mail servers.
- Update packages for KDE-3.0.1 to make the transition from KDE-3.0
for the SuSE Linux 8.0-i386 distribution can be found at the usual
path on our ftp server ftp.suse.com, also available through our
online update utility YOU. These packages have now been replaced
to fix two vulnerabilities in khtml. One of them is similar to the
"Opera javascript protocoll vulnerability", published by Andreas
Sandblad on bugtraq. The weakness allows to inject JavaScript
code in a subframe that the parent frame should not have access to.
The other problem is of a similar gravity, giving the update a
comparatively uncritical magnitude.
We wish to express our gratitude to the KDE developers and particularly
to Dirk Mueller who fixed this problem instantly.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE Linux AG makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPP7MvHey5gA9JdPZAQF7bQf/eqKtGb6T7QVlaYpM/sy3ap+fho9TzuRr
qjJ3Sm+xJQGb7zyAvRVv/KKmNjhCd01xtxKyN0a9IhtR+Rjcr5/oxlgQxmLOurb/
h/CZxjNTGY4LKPO6mQZFSWcs5qU3qzuU3HnN6yq/OKKWFTT0w58TprQ/pCp3ldUf
BoQpCQ+wQFPNURCmiEPNMZdmA4zcdqnQvpquPKScVTVTfrUF0xIJNjlrTjJclFwf
zSHi/SFUfKndmV/yjg3lVJaDbRrmDcyNXWxFKEWoBlYrlZM0ixxGhLqKi2VDghrM
NBGkw23TRyjYt/T/x4qYLQE0EjfSsnplPwKa+fjCpdhub84xhEITUQ==
=deyr
-----END PGP SIGNATURE-----
1
0
29 May '02
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: tcpdump/libpcap
Announcement-ID: SuSE-SA:2002:020
Date: Wed May 29 14:00:00 MEST 2002
Affected products: 6.4, 7.0, 7.1, 7.2, 7.3, 8.0,
SuSE Linux Database Server,
SuSE eMail Server III,
SuSE Firewall Adminhost VPN,
SuSE Linux Admin-CD for Firewall,
SuSE Linux Live-CD for Firewall,
SuSE Linux Enterprise Server for S/390,
SuSE Linux Connectivity Server,
SuSE Linux Enterprise Server 7
Vulnerability Type: remote command execution
Severity (1-10): 6
SuSE default package: yes
Other affected systems: All systems with vulnerable tcpdump.
Content of this advisory:
1) security vulnerability resolved: Buffer overflow in tcpdump.
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The tcpdump program may be used to capture and decode network traffic.
Tcpdump decodes certain packets such as AFS requests in a wrong way
resulting in a buffer overflow. Since running tcpdump requires root
privileges this may lead to a root compromise of the system running
tcpdump. We strongly recommend an update for administrators using
tcpdump to monitor their networks since the only safe workaround is to
not use it at all.
Additionally to the fixed tcpdump packages we provide new libpcap
packages. Libpcap on which most network monitoring programs rely also
contained overflows which however are only exploitable by local attackers
if you installed programs using libpcap setuid. This is not found in a
default install.
More information about tcpdump and libpcap may be found at
http://www.tcpdump.org
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/tcpdump-3.6.2-300.i386.rpm
f6b5499e4857575fa162ae24cde181c8
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/tcpdump-3.6.2-300.src.rpm
2dd114976f858d0a66c83f409dbf25a0
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/tcpdump-3.6.2-300.i386.rpm
dc7fba8709f74476ee463e3b7d3d9042
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/tcpdump-3.6.2-300.src.rpm
d2d6a940df5c40e54a6b30e3698458ef
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/tcpdump-3.4a6-376.i386.rpm
601bc08d351e8100767bbfd502efd44b
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/tcpdump-3.4a6-376.src.rpm
af87a4ad56fc853800c6af5982899f18
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/tcpdump-3.4a6-375.i386.rpm
a3251d65bfa05948ce3796ac9e5fdf5b
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/tcpdump-3.4a6-375.src.rpm
84ba69db15e1ff569cf674f7d61428f1
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n1/tcpdump-3.4a6-374.i386.rpm
63d57b2062a91d5fabeb43a5543d245e
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/tcpdump-3.4a6-374.src.rpm
204195b01bc25f84209029bed0eb00cd
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/n1/tcpdump-3.4a6-372.i386.rpm
ebb48c115355dc4ba1f45b1f8c36f9aa
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/6.4/zq1/tcpdump-3.4a6-372.src.rpm
d2087aea083c4f6b93a518eee00c979e
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/tcpdump-3.6.2-58.sparc.rpm
bb422a4c2d025d3b8a805345a200576a
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/tcpdump-3.6.2-58.src.rpm
e0f85bd701865ca1f3d0923d1b9eb24c
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/n1/tcpdump-3.4a6-318.sparc.rpm
eaf6237823690fe4cb72df39b2b75a5f
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/zq1/tcpdump-3.4a6-318.src.rpm
458f7aaa2ed33606007d345d371bf8c4
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/n1/tcpdump-3.4a6-318.sparc.rpm
6137a3ecadd2bfd95b51039fef52187b
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/zq1/tcpdump-3.4a6-318.src.rpm
0227535bdc5f7bd6980e77737cc6182c
AXP Alpha Platform:
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/tcpdump-3.4a6-329.alpha.rpm
614dfa16b71456692bc1d92b9db0998b
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.1/zq1/tcpdump-3.4a6-329.src.rpm
e5a05bdbe3d5a29f0840c488e703268b
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n1/tcpdump-3.4a6-330.alpha.rpm
0f1fbdfdcf8f4e1a90424df1b3ad05bc
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/tcpdump-3.4a6-330.src.rpm
d48289b8926c3fa7602b6ad026ae4130
SuSE-6.4
ftp://ftp.suse.com/pub/suse/axp/update/6.4/n1/tcpdump-3.4a6-330.alpha.rpm
bf9ef22920ff73802e3b02005476527b
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/6.4/zq1/tcpdump-3.4a6-330.src.rpm
1fa595c3febfc97f45642faffdd1dfb1
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/tcpdump-3.6.2-189.ppc.rpm
303f6a00defddc3b8a3be1ab386021cf
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/tcpdump-3.6.2-189.src.rpm
552355e0f15582d47d64fd3a97542cf3
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/tcpdump-3.4a6-317.ppc.rpm
4dd468ba517be7c7f52a8b2ac7c2beb0
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/tcpdump-3.4a6-317.src.rpm
69be109e360246794c66ed55e199ee95
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n1/tcpdump-3.4a6-316.ppc.rpm
1b51e5529fa559d8453588f09d9b8585
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/tcpdump-3.4a6-316.src.rpm
20d1da2b898a483df771809747851967
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/n1/tcpdump-3.4a6-315.ppc.rpm
97cd7574108f3fcb9f52a7213d626481
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/zq1/tcpdump-3.4a6-315.src.rpm
67c63c89e26c2a17df6fef3585f41481
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- Perl-Digest-MD5
The Perl Digest-MD5 module fails to handle utf8 characters properly
and thus calculates wrong hash sums for certain input. New packages
are already available on our ftp servers.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE Linux AG makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPPS7U3ey5gA9JdPZAQGGzQgAluto4ljBhn1o2NZUAQeyX57dCXBwF7X+
d3Y+R7EkUG9jktmIuRqpUBIRz21ckTLGbZkXblNZYKl/EPYTZDGYaG3/GfYJ8NKN
5X/VL1LY+WqPYzEMQtkIBGIBIltD6jTQAJ4TSnKqvYAFajW2lN4ZahDQET1Xr9ma
Vw5DnmPVsW1kYCbgL8qz+q0u4d7IUqF07A2iTUeGpfy4cyD8KbYFoZM3UeKe1T6g
73TlkbeP1ifZDOetGGQBc/wVpKUUUrp6srDJc1rUh2sEB0u5+c3o0zawP1ltPqZV
KyVuofDRLs+BwRHm10eMbjbTsm9d1Wv8TZwSRU27Zh8SDZxqMiF0LQ==
=7hKT
-----END PGP SIGNATURE-----
--
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer(a)suse.de - SuSE Security Team
~
1
0
22 May '02
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: dhcp/dhcp-server
Announcement-ID: SuSE-SA:2002:019
Date: Wednesday, May 22th 2002 13:30 MEST
Affected products: 7.2, 7.3, 8.0
SuSE Linux Database Server
SuSE eMail Server III
SuSE Linux Enterprise Server for S/390
SuSE Linux Connectivity Server
SuSE Linux Enterprise Server 7
Vulnerability Type: remote command execution
Severity (1-10): 4
SuSE default package: no
Other affected systems: all systems using ISC DHCP server 3.x
Content of this advisory:
1) security vulnerability resolved: format string bug in dynamic DNS
code
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The "Dynamic Host Configuration Protocol" (DHCP) server from the Internet
Software Consortium allows hosts on a TCP/IP network to request and be
assigned IP addresses, and also to discover information about the network
to which they are attached.
A remote exploitable format string vulnerability was found in the logging
routines of the dynamic DNS code of dhcpd. This vulnerability allows an
attacker, usually within the LAN served by the DHCP server, to get remote
root access to the host running dhcpd.
The dhcp/dhcp-server package is not installed by default nor is the
dynamic DNS feature enabled by default.
As temporary workaround the dynamic DNS feature could be disabled via
dhcpd's config file with the following lines:
ddns-update-style none;
ddns-updates off;
After updating the package or modifying the config file you have to run:
rcdhcpd restart
as root to restart all instances of running dhcpd processes.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n2/dhcp-server-3.0.1rc6-8.i386.…
754569c059f5f2c4f71397f6c6498f53
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/dhcp-3.0.1rc6-8.src.rpm
82ab4455ae86a932a746778ca0cf06f1
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/dhcp-3.0rc12-47.i386.rpm
58bdf5e4e0622ba280fad0d649a36bdd
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/dhcp-3.0rc12-47.src.rpm
20abdc3bad4810971aa4cc959c133a9e
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/dhcp-3.0rc4-27.i386.rpm
826ffc2524ad6a6b3b746e3c5e0e5413
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/dhcp-3.0rc4-27.src.rpm
7bfd527698beef5a83e60577e7e02cfb
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n2/dhcp-3.0rc12-22.sparc.rpm
15ec49d27e7f8b61ec22616484e43996
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/dhcp-3.0rc12-22.src.rpm
1e3f0ee6da5684a49b31908f0e6ac9dd
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/dhcp-3.0rc12-32.ppc.rpm
76914c072100dff6fdf781ed81f7afeb
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/dhcp-3.0rc12-32.src.rpm
9ac78f35a529c24315f11184555c7f81
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- tcpdump/libpcap
Various security and non-security related bugs were found in the code
of tcpdump and libpcap. New RPMs are currently being build.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE Linux AG makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3in
Charset: noconv
iQEVAwUBPOvMjXey5gA9JdPZAQF70Qf9EovJ5FK0nGSa9uMVcoCiCvhRwdfFSCBe
HNx1LgX9Q+bHEo9dPjqYxyNxN4HTGwWMbVyix/lQ2CDUOzxf0gxp+30R1E++RUdC
sOCXwiPTkrcuMhOhwq3j7D2YUoxkpXpK17Eq+ZxHB6Z89mJEFPrkVuSriLdl07a4
6xAEH3koek3QFi18IX6JAzaQtG5A8qPfFRdE6mBrNk3a0zWH9mBzUUeYw+a4gaF3
497vfBdu/cffxVqyLBCqZlnUM6gs9YzBpbDNz3T3uNqQ1cjhl91b92x0MFatqiEj
Nn3lTXXPklob6S9JoaONvvw3diQ31F2gor+sZNTRv/6q9zNUv3IUdA==
=KL4d
-----END PGP SIGNATURE-----
Bye,
Thomas
--
Thomas Biege <thomas(a)suse.de>
SuSE Linux AG,Deutschherrnstr. 15-19,90429 Nuernberg
Function: Security Support & Auditing
"lynx -source http://www.suse.de/~thomas/contact/thomas.asc | pgp -fka"
Key fingerprint = 51 AD B9 C7 34 FC F2 54 01 4A 1C D4 66 64 09 83
--
Trete durch die Form ein, und trete aus der Form heraus.
1
0
16 May '02
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: lukemftp, nkitb, nkitserv
Announcement-ID: SuSE-SA:2002:018
Date: Wednesday, May 15th 2002 12:30 MEST
Affected products: 6.4, 7.0, 7.1, 7.2, 7.3, 8.0
SuSE eMail Server III
SuSE Linux Database Server
SuSE Firewall Adminhost VPN
SuSE Linux Live-CD for Firewall
SuSE Linux Admin-CD for Firewall
SuSE Linux Connectivity Server
SuSE Linux Enterprise Server 7
SuSE Linux Enterprise Server for S/390
Vulnerability Type: remote command execution
Severity (1-10): 3
SuSE default package: yes
Other affected systems: all systems using lukemftp
Content of this advisory:
1) security vulnerability resolved: buffer overflow while parsing PASV
command
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
Lukemftp (ftp(1), /usr/bin/ftp, /usr/bin/pftp) is a compfortable ftp
client from NetBSD.
A buffer overflow could be triggered by an malicious ftp server while the
client parses the PASV ftp command. An attacker who control an ftp server
to which a client using lukemftp is connected can gain remote access to
the clients machine with the privileges of the user running lukeftp.
The lukemftp RPM package is installed by default.
You need to update the package, as no temporary workaround is possbible.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/lukemftp-1.5-249.i386.rpm
0ae28f7ca49157bfa5783626d3e82cef
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/lukemftp-1.5-249.src.rpm
d9fc530c338ea2de122b6a4a1f89a627
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/lukemftp-1.5-256.i386.rpm
aeb64a5ba64b5b334dfcf244423a9809
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/lukemftp-1.5-256.src.rpm
cc94b939696c76cda0fec683d12ff384
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/lukemftp-1.5-256.i386.rpm
94812aeb3b164a67b0c85b0c9a61a450
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/lukemftp-1.5-256.src.rpm
5cd6642505a68be70ce9eac3ba5dd311
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/lukemftp-1.5-251.i386.rpm
836df6046ce81fcc82e9939fde5003d1
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/lukemftp-1.5-251.src.rpm
788bc38fed7b486e857b5d780451b7a7
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/a1/nkitb-2002.5.8-0.i386.rpm
e6199c28c700461a7ae10c3f7fba73a8
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/nkitb-2002.5.8-0.src.rpm
e1c6379846842ea62a5c484167102cae
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n1/nkitserv-2002.5.8-0.i386.rpm
50bb6a7ae3f450ad530ad92ae8dad3e1
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/a1/nkitb-2002.5.9-0.i386.rpm
6950a272cf3a30a02860cf179387a9e8
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/6.4/zq1/nkitb-2002.5.9-0.src.rpm
09d7ac9ba5e1420eeddb016a6d812067
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/lukemftp-1.5-77.sparc.rpm
295d90e7bfeb94f27f542616e016bd65
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/lukemftp-1.5-77.src.rpm
42e213cfc930e0a00aa871e9996d3cba
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/n1/lukemftp-1.5-76.sparc.rpm
50fc0f99b42347aee746450624ed4817
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/zq1/lukemftp-1.5-76.src.rpm
01cdff7ff9f908466b8d3269fe4529c5
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/a1/nkitb-2002.5.8-0.sparc.rpm
210230a1a085af9f777f047a9edfa9f5
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/zq1/nkitb-2002.5.8-0.src.rpm
b0e476e5ba4e9211cab20442f35b49d8
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/n1/nkitserv-2002.5.8-0.sparc.r…
70b063b1901c8655a23b008cc6ef4036
AXP Alpha Platform:
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/lukemftp-1.5-89.alpha.rpm
27c6ca255ef42c7e6851f309d6474fcd
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.1/zq1/lukemftp-1.5-89.src.rpm
fdc27d3abae5bf6dfcd06907d2afc278
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/a1/nkitb-2002.5.8-0.alpha.rpm
2c397f234a2326baba98a4da8dff601a
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/nkitb-2002.5.8-0.src.rpm
437a49653372205c4218e7283422fd6b
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n1/nkitserv-2002.5.8-0.alpha.rpm
e2943d09b3bf82883bfd62aff74e500b
SuSE-6.4
ftp://ftp.suse.com/pub/suse/axp/update/6.4/a1/nkitb-2002.5.9-0.alpha.rpm
33b7a7b2f81dc78035450c0643786c83
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/6.4/zq1/nkitb-2002.5.9-0.src.rpm
60960a0129207b317fc22089f6203589
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/lukemftp-1.5-154.ppc.rpm
fd6bc23e95cd7a19283dd4067f376bb3
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/lukemftp-1.5-154.src.rpm
bb301c6487a09a2b3d82ce9b000b8f69
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/lukemftp-1.5-150.ppc.rpm
023a43cba32d976d0a5665365242647b
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/lukemftp-1.5-150.src.rpm
53f38c8f4a3205b3bedbc76b209d177b
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/a1/nkitb-2002.5.8-0.ppc.rpm
101d5af039c262f7b7e7d50598fa064c
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/nkitb-2002.5.8-0.src.rpm
ed39244bcb57fad7b92287f5c9d26e3d
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n1/nkitserv-2002.5.8-0.ppc.rpm
b6146585ab16d1d507e04f066f21f5d6
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/a1/nkitb-2002.5.9-0.ppc.rpm
10b66b58b887a1899df7e16b15689bfb
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/zq1/nkitb-2002.5.9-0.src.rpm
954dcd26ef2eb777e737621927f98835
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- imap
A bug report about a buffer overflow in the RFC1730 code of the wu-imap
eMail server was published. SuSE Linux' imap packages were compiled
without RFC1730 support, so SuSE Linux is not vulnerable to this bug per
default.
- dhcp
A format string bug was found in the DynamicDNS (DDNS) code of ISC's
DHCP server software. New RPMs are currently being build.
- imlib
Due to packaging failures we have to re-release the imlib packages
which should be available within the next days. This update addresses
missing dependencies and affects applications like xcdroast.
- perl-Digest-MD5
A bug was found in the UTF8 interaction between perl and perl-Digest-MD5
which leads into failures while verifying the MD5 hash.
New RPMs are currently being build.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE Linux AG makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3in
Charset: noconv
iQEVAwUBPOOaMney5gA9JdPZAQHhdggAmcDEmc+F15x5VI6LQhUyONMBQHr5HUAb
Lb3iR3qAGEAxyyUL4VnSX18BNcTxMfTRVUqiwHhihTfAnDun70eObGEiJjPSEVwG
jEACz3kFOz1HfGuowovn1O8VrK8kRcfBwhAUKSwgr2aXEgP+FbSKpdQbH6sDJVpR
HUBa/YLhYGF9PiJ2ev+i5nt+1mYu4BMA22w1DVyHuSGzr3yPzo/wPUcak+J2VZHJ
jgKm4hYpUHnRwU3CV/RPQOAgzV5OYp9aKE5wQU5bx35gvwl8U5RG00lcxltdjKAJ
GGxKzvciEduusNPGWKEShjOGSMWiTwB3goDomv1KG6PwBmaxDSE4uA==
=0IAE
-----END PGP SIGNATURE-----
Bye,
Thomas
--
Thomas Biege <thomas(a)suse.de>
SuSE Linux AG,Deutschherrnstr. 15-19,90429 Nuernberg
Function: Security Support & Auditing
"lynx -source http://www.suse.de/~thomas/contact/thomas.asc | pgp -fka"
Key fingerprint = 51 AD B9 C7 34 FC F2 54 01 4A 1C D4 66 64 09 83
--
Trete durch die Form ein, und trete aus der Form heraus.
1
0
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: shadow/pam-modules
Announcement-ID: SuSE-SA:2002:017
Date: Thu May 16 12:00:00 MEST 2002
Affected products: 8.0
Vulnerability Type: local privilege escalation
Severity (1-10): 5
SuSE default package: yes
Other affected systems: No.
Content of this advisory:
1) security vulnerability resolved: write() disruption in shadow utils
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The shadow package contains several useful programs to maintain the
entries in the /etc/passwd and /etc/shadow files.
The SuSE Security Team discovered a vulnerability that allows local
attackers to destroy the contents of these files or to extend the group
privileges of certain users. This is possible by setting evil filesize
limits before invoking one of the programs modifying the system files.
Depening on the permissions of the system binaries this allows a local
attacker to gain root privileges in the worst case. This however is not
possible in a default installation.
The bug has been fixed by ensuring the integrity of the data written
to temporary files before moving them to the appropriate location of the
system. There is no workaround so we recommend an update in any case.
It is necessary to update the shadow package as well as the pam-modules
package in order to prevent the truncation attacks.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/a1/shadow-4.0.2-88.i386.rpm
a4e0d03ecf7707eb7ca1f0422cae89f1
ftp://ftp.suse.com/pub/suse/i386/update/8.0/a1/pam-modules-2002.3.9-31.i386…
70322584f014ac3e2dc2dad0beecdefb
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/shadow-4.0.2-88.src.rpm
33af2433d9a8822202e9f6ebdc6d3e2c
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/pam-modules-2002.3.9-31.src…
1bc5bbd169ffe5c35caa0a4ce681dcc0
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- leafnode
The permissions of "/etc/leafnode" have been corrected. Please update
to the newly available packages if you use leafnode.
- xf86, xmodules, xloader
Incorrect permission checks in certain X11 functions allow local attackers
to read or write shared memory segments they should not have access to.
Corrected packages will soon be available on our ftp-servers.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE Linux AG makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPOOFNney5gA9JdPZAQFT0Af/T03nd1jO+3wcFLfs3Srq5Al9E2SXIdR4
gkEwTbP355ZFUA22ZElhZupX4gAAGxFduXX8s2n/kgfw4nkkY1gY6SG6aAbdvW99
AD6MY2X8HyrzRL3Ox0VO+kAOM1GCqNL0E6Rw5k3wTAErxOZeqgMA9IwjFoGFoRfX
nBeloxZxQvFk8vG2yRPEDh6YVPvrDtAaWdZxAh4K81eOr5/jz+w53If0oY0or62w
Zp5P0+CQbfj/ziJMoWVo9N4tK70il0kVrAvj/PWyobf0nfV6kIFf6F6nOWuge60J
xqX5aM8F16iTYwhi6/AGAQckkCBqFpqxGJbNa05eGjOxerZ7M9tviQ==
=usIl
-----END PGP SIGNATURE-----
--
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer(a)suse.de - SuSE Security Team
~
1
0
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: sysconfig
Announcement-ID: SuSE-SA:2002:016
Date: Wed May 8 12:00:00 MEST 2002
Affected products: 8.0
Vulnerability Type: remote command execution
Severity (1-10): 4
SuSE default package: Yes.
Other affected systems: No.
Content of this advisory:
1) security vulnerability resolved: Quotation problem in ifup-dhcp.
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The ifup-dhcp script which is part of the sysconfig package is responsible
for setting up network-devices using configuration data obtained from a
DHCP server by the dhcpcd DHCP client. It is possible for remote attackers
to feed this script with evil data via spoofed DHCP replies for example.
This way ifup-dhcp could be tricked into executing arbitrary commands as
root. The ifup-dhcp shellscript has been fixed to not source the file
containing the possible evil data anymore.
Even though the sysconfig package is installed by default, this problem
only affects systems with certain dhcp network-setups so only users using
DHCP should update their sysconfig package.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/a1/sysconfig-0.23.14-60.i386.rpm
4d6a9f1a3e1a461ebbea9a6e98f4e894
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/sysconfig-0.23.14-60.src.rpm
d0fdfe02cfc9b7fc32fed8da6c16cf9d
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- mozilla/netscape
The mozilla browser in version 0.9.7 or higher and the netscape browser
in version 6.1 or higher contain a flaw which allows remote sites
to read arbitrary files if the user running the browser has the
permission to do so. Fixed packages for the mozilla browser will be
available soon on our ftp-servers. Patches for the affected netscape
browser are not yet available due to missing fixes from Netscape.
- xpilot
It has been reported that the xpilot server contains a buffer-overflow
which allows remote attackers to execute arbitrary commands as the user
running the server. The overflow has been fixed and new xpilot packages
are available on our ftp-servers. Please update to the newest xpilot
packages if you used to run this program.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE GmbH makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPNj243ey5gA9JdPZAQFDcQf8DMhbYdX+UsDGAwO4QpPylxxnh31Dt476
czcCmCH8XbzyNxIhdQeYAkSJ0rkRJD7xC+lgXjQbAv7TzAFsl6FGnsZDgB/b62z8
2vG+1iWoxYwQTSl7g7kpsQ+pDuZ8737ZQr7DY2gg9nLK4xPngt/C8TuBDVFIcqcE
DrMlfUAWTiAvIVAPZxVWrbOjqVG6B00LeiHu/kQkOgXKQffqKKbNUa9Iyu5Fb/6Q
CNO311fw2HCs4Ef7veZXJGmua8TGbbnj7ydWVmteLdYVbxEZ4faIFpJPiuJAcHI3
C49BNAEKo5GEBtvq/CPO35oK97uO5xiEhTDWA76Vbl27kyRluvGdqQ==
=spzT
-----END PGP SIGNATURE-----
--
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer(a)suse.de - SuSE Security Team
~
1
0
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: imlib
Announcement-ID: SuSE-SA:2002:015
Date: Tuesday, May 7th 2002 11:30 MEST
Affected products: 6.4, 7.0, 7.1, 7.2, 7.3, 8.0
Vulnerability Type: remote privilege escalation
Severity (1-10): 3
SuSE default package: yes
Other affected systems: all systems/applications using imlib
Content of this advisory:
1) security vulnerability resolved: imlib fallback and Denial-of-Service
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The imlib library can be used by X11 applications to handle various
kinds of image data.
Imlib could, under certain circumstances, revert to using a netpbm
library which is well known to have security problems and should not
be used for handling untrusted data. Furthermore a heap corruption
could occur in the imlib code.
An attacker could send a maliciously formated image file to trigger
a Denial-of-Service attack or even execute arbitrary code on the
victim's machine.
Thanks go to Al Viro and Alan Cox who discovered these bugs.
The imlib RPM package is installed by default and affects all applications
linked against imlib, like imager viewers, browsers, mail clients and
so on.
About 140 applications shipped with the SuSE Linux distribution depend
on imlib. You need to update your system, as no temporary workaround is
possbible.
Please run ldconfig(8) as root after updating imlib and restart all
applications using imlib.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra1/imlib-1.9.10-324.i386.patc…
9137d95a9205a335871a71341c2c70b4
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra1/imlib-1.9.10-324.i386.rpm
4abd84a67aacb2c2fa21582e228e6a1d
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra3/imlib-config-1.9.10-324.i3…
43103d0ff1e60f008499a69519d722d3
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra3/imlib-config-1.9.10-324.i3…
02df11424f082e4aed1c93527f7bab69
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra3/imlib-devel-1.9.10-324.i38…
7680c38f5fef811bc96ff2fc00baafad
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gra3/imlib-devel-1.9.10-324.i38…
bb449e5db3bf0827168b78d7636accac
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/imlib-1.9.10-324.src.rpm
d7cb0ddd0e18d645191f967b5b6e8109
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/gra1/imlib-1.9.10-305.i386.rpm
b114e4ea9babf4ac8bd241674b0be0fd
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/gra2/imlib-config-1.9.10-305.i3…
7b3cd1c19161ed500bc4a0306eb66d0c
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/gra2/imlib-devel-1.9.10-305.i38…
41af6a469645a4ce4399935604cbf4c0
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/imlib-1.9.10-305.src.rpm
1839a719883e4aa5e543ee1bd22dc780
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/gra1/imlib-1.9.9-100.i386.rpm
9ec9fb90418a6ba76432334cb7e15bb8
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/gra2/imlib-config-1.9.9-100.i38…
584e88a451341910524740cc54ca9c64
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/gra2/imlib-devel-1.9.9-100.i386…
c8c25f5396d565f75f68d48d7911813b
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/imlib-1.9.9-100.src.rpm
a5691ba54118a52454d394e346a6b8b4
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/gra1/imlib-1.9.8.1-132.i386.rpm
dc9d57492cd4faa497e23e14fcf5e57b
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/gra2/imlib-devel-1.9.8.1-132.i3…
58f03af3039c42db5b5a9d1a6acd9c27
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/gra2/imlibcfe-1.9.8.1-132.i386.…
b82aa8abda460e45094fb4a0d683971f
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/imlib-1.9.8.1-132.src.rpm
f16db540325f4626aa5fda6ab5aa196b
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/gra1/imlib-1.9.8.1-132.i386.rpm
c089d699c31addadba09fd967677e535
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/gra2/imlibcfe-1.9.8.1-132.i386.…
ee3c4bf8ab5e7068afcfb7160c38653f
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/gra2/imlibdev-1.9.8.1-132.i386.…
253759ffd47eb19831e61c52673ebc6f
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/imlib-1.9.8.1-132.src.rpm
2bb8b096627c72e25949d4e22fc26c3a
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/gra1/imlib-1.9.8-13.i386.rpm
b3175095dade1c545822b42707a99820
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/gra2/imlibcfe-1.9.8-13.i386.rpm
a54bfa0d5b6333c20497dfd6ae1c65f6
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/gra2/imlibdev-1.9.8-13.i386.rpm
6d5815e9cfc1e9020dd758fcf3e15f0b
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/6.4/zq1/imlib-1.9.8-13.src.rpm
ce83d062fb32cf34ed6921490c732a51
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/gra1/imlib-1.9.10-110.sparc.rpm
58f0df8b16d05b7b28d919c53b20ddfd
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/gra2/imlib-config-1.9.10-110.s…
92c1e1a5a67b0a73197f793101af5955
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/gra2/imlib-devel-1.9.10-110.sp…
744db88a54bcff79068a7b2392e34fc2
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/imlib-1.9.10-110.src.rpm
fa4c576fea3185bc7624e50620dbaaf5
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/gra1/imlib-1.9.8.1-109.sparc.r…
dc3336004bc77ceca74035cb05b050f9
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/gra2/imlib-devel-1.9.8.1-109.s…
a27820491016c5ff1fac5706b7042158
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/gra2/imlibcfe-1.9.8.1-109.spar…
b8b28901c088bc6763f462753ca58b7c
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/zq1/imlib-1.9.8.1-109.src.rpm
7605166c8ee6fa6439ade68e0d67c5c6
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/gra1/imlib-1.9.8.1-109.sparc.r…
8b1e28d9aa91061aed4569015e058fac
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/gra2/imlibcfe-1.9.8.1-109.spar…
01c5dae090bfe25d641d3389a11c16c2
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/gra2/imlibdev-1.9.8.1-109.spar…
3be7654afc64fb5a10c145f67dce9ba3
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/zq1/imlib-1.9.8.1-109.src.rpm
6531693204e86106ceee748758038a07
AXP Alpha Platform:
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/gra1/imlib-1.9.8.1-114.alpha.rpm
a84242de9afeec0b77f9d85b54f51f5b
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/gra2/imlib-devel-1.9.8.1-114.alp…
a2829f4eba557fbc3160b6b4ffec0ac5
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/gra2/imlibcfe-1.9.8.1-114.alpha.…
691b3d75dab0a3487b9f57c9b3501b17
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.1/zq1/imlib-1.9.8.1-114.src.rpm
58697086bf51f5231a1708765db8312c
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/gra1/imlib-1.9.8.1-114.alpha.rpm
fbbf3f167844f0b046aafc14fed3b50e
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/gra2/imlibcfe-1.9.8.1-114.alpha.…
e5a8c05ca99ce4b38de47b35258423d7
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/gra2/imlibdev-1.9.8.1-114.alpha.…
26cc11948b4d61d6e4c0aa35472d2d7d
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/imlib-1.9.8.1-114.src.rpm
90df4b7a6860281ad6130b09e7e634e3
SuSE-6.4
ftp://ftp.suse.com/pub/suse/axp/update/6.4/gra1/imlib-1.9.8-12.alpha.rpm
2b231d47fed0f5ac88299abbb6abb1cd
SuSE-6.4
ftp://ftp.suse.com/pub/suse/axp/update/6.4/gra2/imlibcfe-1.9.8-12.alpha.rpm
99b4a22d820a3d846fc1bf0ca94843e4
SuSE-6.4
ftp://ftp.suse.com/pub/suse/axp/update/6.4/gra2/imlibdev-1.9.8-12.alpha.rpm
a7e9b77c92c28fe6bd07d4d8634a5253
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/6.4/zq1/imlib-1.9.8-12.src.rpm
11a996b48ee33c34b34acffad3a2a56c
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/gra1/imlib-1.9.10-199.ppc.rpm
f9c093c06636b62507846c6679e1e86d
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/gra2/imlib-config-1.9.10-199.ppc…
973e484ba78847b5c47d5d6ef3972f56
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/gra2/imlib-devel-1.9.10-199.ppc.…
e06812ab04e4cbdc781d8e8d29dc3372
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/imlib-1.9.10-199.src.rpm
8f85b9a40d36d328deb20b3255ddc05c
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/gra1/imlib-1.9.8.1-103.ppc.rpm
4a22c12194b6f1b80123a3466fe944c3
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/gra2/imlib-devel-1.9.8.1-103.ppc…
85139eb233c567783c053f110baadb66
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/gra2/imlibcfe-1.9.8.1-103.ppc.rpm
ae31194e59d40267b36e38344b1ad139
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/imlib-1.9.8.1-103.src.rpm
6558c6ca5bee620485fd52a9a7ec316d
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/gra1/imlib-1.9.8.1-103.ppc.rpm
e34ddef90edd1effb95771b5d7f6f935
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/gra2/imlibcfe-1.9.8.1-103.ppc.rpm
13eb42a163f919c9a4c097d8dc55a4a3
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/gra2/imlibdev-1.9.8.1-103.ppc.rpm
9e73db46c744ee38118c9cd4b97bda7a
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/imlib-1.9.8.1-103.src.rpm
d321ee18493970c45b232362653dc447
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/gra1/imlib-1.9.8-13.ppc.rpm
3d255a622cd006656a662b0e7a5efb87
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/gra2/imlibcfe-1.9.8-13.ppc.rpm
311ac75ac7622c6b453c5d6ed5ef9c28
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/gra2/imlibdev-1.9.8-13.ppc.rpm
c5a86e6598a9fc801f56533e060dcc61
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/zq1/imlib-1.9.8-13.src.rpm
294626d55b89e1a5b940b4441172b578
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- screen
A security report about a locally exploitable bug in screen's braile code
was published on Bugtraq. SuSE ships screen without this code enabled.
On SuSE version 8.0 screen isn't even running with higher privileges
anymore.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE Linux AG makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3in
Charset: noconv
iQEVAwUBPNfA/Hey5gA9JdPZAQEaDAf9E66E718T82XQD2DqM+ck8vPnJAM5fP9U
u+k+tCH8NuvJkTxloqK3lTip4tRafqbanqj4+I3r7z5C9Tu1lzZZljgiFNPxRhST
mwqNx+N0Jl72tu2L5YfzgmGI4RLP4S0idjLidgTQLpZa+2bGiejd5gpjZZmf1yzI
BK46SjCH4TC0khhqKHvUnjZrOS7RUwFfSdSlpSnNjfaX8JNj6VWUhA8PSOyVh4JX
uPDceih0EGHwNaFE7veX9yAj68X75ATPTpqj984zo8blGYbS5fBe5A3y3Wk5d5FX
IqKb1V6GGm0gyfD45gMRuzK1ZwGYeB3YDLO/HJKUgrujsYs1braLEg==
=Y/Qi
-----END PGP SIGNATURE-----
Bye,
Thomas
--
Thomas Biege <thomas(a)suse.de>
SuSE Linux AG,Deutschherrnstr. 15-19,90429 Nuernberg
Function: Security Support & Auditing
"lynx -source http://www.suse.de/~thomas/contact/thomas.asc | pgp -fka"
Key fingerprint = 51 AD B9 C7 34 FC F2 54 01 4A 1C D4 66 64 09 83
--
Trete durch die Form ein, und trete aus der Form heraus.
1
0
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: sudo
Announcement-ID: SuSE-SA:2002:014
Date: Tue Apr 30 16:00:00 MEST 2002
Affected products: 6.4, 7.0, 7.1, 7.2, 7.3, 8.0,
SuSE Firewall Adminhost VPN,
SuSE Linux Admin-CD for Firewall,
SuSE Linux Enterprise Server,
SuSE Linux Connectivity Server
Vulnerability Type: local privilege escalation
Severity (1-10): 6
SuSE default package: yes
Other affected systems: All systems with sudo installed.
Content of this advisory:
1) security vulnerability resolved: Heap overflow in sudo.
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The sudo program allows local users to execute certain configured
commands with root priviledges. Sudo contains a heap overflow in its
prompt assembling function. The input used to create the password prompt
is user controlled and not properly length-checked before copied to certain
heap locations. This allows local attackers to overflow the heap of sudo,
thus executing arbitrary commands as root.
We would like to thank GlobalInterSec for finding and researching
this vulnerability.
As a temporary workaround you may remove the setuid bit from sudo by
issuing the following command as root: "chmod -s /usr/bin/sudo".
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
i386 Intel Platform:
SuSE-8.0
ftp://ftp.suse.com/pub/suse/i386/update/8.0/ap1/sudo-1.6.5p2-79.i386.rpm
b54f68ff4b32f9d920f2f1ff887d1ddc
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/sudo-1.6.5p2-79.src.rpm
fd1ccf6fe52c6b999c5ed24a2f3a4e65
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/ap1/sudo-1.6.3p7-83.i386.rpm
80edbf5caf02c519cf2c01d6ba76d22f
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/sudo-1.6.3p7-83.src.rpm
77962932840740ce5e3dfe57a887592d
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/ap1/sudo-1.6.3p6-92.i386.rpm
669aa8db134e39f462cb9f2648f6735f
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/sudo-1.6.3p6-92.src.rpm
249b1ef0135dcfede3648982900e277c
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/ap1/sudo-1.6.3p6-91.i386.rpm
6b3b84f0a4c687e91da179937b87048a
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/sudo-1.6.3p6-91.src.rpm
bf59a6b200a0fb130f3528ce23698be0
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/ap1/sudo-1.6.3p6-90.i386.rpm
5b67ef9fed383242111953d942c62174
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/sudo-1.6.3p6-90.src.rpm
c35f6390b360500b7b649e4590a748cc
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/ap1/sudo-1.5.9p1-87.i386.rpm
82d98116eccc73c7a0ce03a51e9b5378
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/6.4/zq1/sudo-1.5.9p1-87.src.rpm
e75e2608036a963a7339fe4632a2550b
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/ap1/sudo-1.6.3p7-33.sparc.rpm
bd492b6d601ceb30486e3e970a2211a3
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/sudo-1.6.3p7-33.src.rpm
d2435d180cdd76647e1f1416e93c2420
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/ap1/sudo-1.6.3p6-37.sparc.rpm
bbad36265f93fac25d59f8c26b1ccd52
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/zq1/sudo-1.6.3p6-37.src.rpm
a328d2eb0fdc816341a68febfeb5a33a
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/ap1/sudo-1.6.3p6-36.sparc.rpm
48e7b360b45bae0b3e9e90b3bf945f75
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/zq1/sudo-1.6.3p6-36.src.rpm
bd8f11a8916340e0d243ae1cc647df26
AXP Alpha Platform:
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/ap1/sudo-1.6.3p6-40.alpha.rpm
4505dd58fe309ef0a4515db6a6980ec4
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.1/zq1/sudo-1.6.3p6-40.src.rpm
85dfbe40da4d93d54d3c16f6489a7f32
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/ap1/sudo-1.6.3p6-40.alpha.rpm
b67858459774e5e04c9c22e84d5899ff
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/sudo-1.6.3p6-40.src.rpm
6d0537068d16785bfdbca936c6395abb
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/ap1/sudo-1.6.3p7-65.ppc.rpm
1734f578b1fa87c26e51a11e3dc90d18
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/sudo-1.6.3p7-65.src.rpm
ebff8b3e7b86ef9bb69fb13da37903ce
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/ap1/sudo-1.6.3p6-45.ppc.rpm
4318adbde184c1c8fff6eb581f02c11e
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/sudo-1.6.3p6-45.src.rpm
771f9e7f6d1fc1ba4df119147e48ddcd
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/ap1/sudo-1.6.3p6-45.ppc.rpm
6ae150cfa793f20e49ed751aa686fdea
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/sudo-1.6.3p6-45.src.rpm
ede5fedf45ffe6b59c43e082fcef50f4
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/ap1/sudo-1.5.9p1-85.ppc.rpm
0677a205615f631a41ca308be03db7bd
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/zq1/sudo-1.5.9p1-85.src.rpm
71da4a7d43043b20eefd5e05048616d8
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- ifup-dhcp could be tricked into executing arbitrary
commands as root by DHCP servers handing out illegal values (e.g.
containing spaces), because it sourced dhcpcd's info file, where
not all variable values are quoted. This problem has been fixed.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE GmbH makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPM6l7Hey5gA9JdPZAQHErAf/dsMrQSaSHlJHFirNNw9XTsyHFb8uxArI
JRgmYIQZValzHicRhxXwRTYRPta3jDx40HH2UqY3VxgWMcHl5fRDne6inYNqlNg5
N70ER3lnHhFyei5er3sX/Rx9sOM/4ONXOk5ZsD/Bdooj0pGJ5hcU9xI1akNxm76k
C1B4I8NW7Z9BnH1tiekNYChRv+lG9cw73ElpHGBNJNt0yIpWp3/idjG8/+J9YUod
ToRV7owlXwTK/N7DTiYbOVTnRZOGKmRc7WC11xPL19xuIDT8GcmHH590jbCWaYNp
DWSoooGuP1w1M1JSS/b+oSIDk4j6/5u9xGmSolDUjjHK/VKjY+dE7w==
=lMC8
-----END PGP SIGNATURE-----
--
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer(a)suse.de - SuSE Security Team
~
1
0
29 Apr '02
-----BEGIN PGP SIGNED MESSAGE-----
______________________________________________________________________________
SuSE Security Announcement
Package: radiusd-cistron
Announcement-ID: SuSE-SA:2002:013
Date: Mon Apr 29 13:00:00 CEST 2002
Affected products: 6.4, 7.0, 7.1, 7.2, 7.3,
Enterprise Server 7
Vulnerability Type: remote command execution
Severity (1-10): 7
SuSE default package: No
Other affected systems: Various radius clients and servers.
Content of this advisory:
1) security vulnerability resolved: digest calculation buffer overflow,
invalid attribute length calculation
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The radius daemon as shipped with the radiusd-cistron package is
responsible for the RADIUS authentication service in networks and therefore
considered a security critical application.
ZARAZA reported security releated bugs in various radius server and
client software. The list of vulnerable servers includes the cistron radius
package. Within the cistron package, a buffer overflow in the digest
calculation function and miscalculations of attribute lengths have been
fixed which could allow remote attackers to execute arbitrary commands on
the system running the radius server. Beside the cistron radius package the
following radius packages have been vulnerable to the same attacks and have
been fixed: freeradius, radiusclient and livingston-radius.
The only workaround for this bug is to disable the radius-server until
the new packages have been installed.
Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command "rpm -Fhv file.rpm" to apply
the update.
Our maintenance customers are being notified individually. The packages
are being offered to install from the maintenance web.
Once you successfully updated your radius packages, make sure you restart
the radius server by issuing the following command as root:
"/etc/rc.d/radiusd restart"
"/etc/rc.d/radiusd" automatically invokes the correct radius-server which
is part of either the cistron, livingston or freeradius package.
i386 Intel Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n3/radiusd-cistron-1.6.4-168.i3…
8215e7113e8937844ab5d2deba8bbb13
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/radiusd-cistron-1.6.4-168.s…
978edf49cf7fa28c5e872bc48ba504ab
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n3/radiusd-cistron-1.6.4-167.i3…
964904ef67f81b2d19f1c8ef2ccc6f61
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/radiusd-cistron-1.6.4-167.s…
6ffd720c4ceb0e0c6d22446178d8bf11
SuSE-7.1
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n3/radiusd-cistron-1.6.4-168.i3…
52ec1da0c4b750fe63d506713ff56c5e
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.1/zq1/radiusd-cistron-1.6.4-168.s…
6d34cc16bf9adcc93eac095570f49748
SuSE-7.0
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n2/cistron-1.6.3-76.i386.rpm
52a9b0c7fcbd45973db6508d155edf21
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/7.0/zq1/cistron-1.6.3-76.src.rpm
a22a646d5f04dd853906db9cc465f14a
SuSE-6.4
ftp://ftp.suse.com/pub/suse/i386/update/6.4/n2/cistron-1.6.2-25.i386.rpm
bed8804bf53822d7f7bcdd54f00a9d89
source rpm:
ftp://ftp.suse.com/pub/suse/i386/update/6.4/zq1/cistron-1.6.2-25.src.rpm
b47877d68465e895fe899da9ba89709d
Sparc Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n3/radiusd-cistron-1.6.4-65.sp…
3230120f925437fd36b648991a3b4851
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/radiusd-cistron-1.6.4-65.s…
713f6f1f7fe4c2987a52b12df6ef2c4a
SuSE-7.1
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/n3/radiusd-cistron-1.6.4-65.sp…
d444432bd863523992620401311f948b
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/zq1/radiusd-cistron-1.6.4-65.s…
ff7a7f432a0a32fbed31a6ee680d5118
SuSE-7.0
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/n2/cistron-1.6.3-4.sparc.rpm
69ee7178a0312685a169386180cd5e9e
source rpm:
ftp://ftp.suse.com/pub/suse/sparc/update/7.0/zq1/cistron-1.6.3-4.src.rpm
71632b60b9b2bee4df06f940088b0ab6
AXP Alpha Platform:
SuSE-7.1
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n3/radiusd-cistron-1.6.4-69.alph…
323032020d8c82724b12904db456c135
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.1/zq1/radiusd-cistron-1.6.4-69.src…
7440831ddb1e394ac6595e9e5bebbff1
SuSE-7.0
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n2/cistron-1.6.3-8.alpha.rpm
4deb36542c3a76a9246618abcd656d96
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/7.0/zq1/cistron-1.6.3-8.src.rpm
77c3cfe8cb64d7c2cd59b81e0e1e26ea
SuSE-6.4
ftp://ftp.suse.com/pub/suse/axp/update/6.4/n2/cistron-1.6.2-20.alpha.rpm
0c39bec71f6671c55b46ed627f2830d9
source rpm:
ftp://ftp.suse.com/pub/suse/axp/update/6.4/zq1/cistron-1.6.2-20.src.rpm
8783c9b8f519a1623bf6df52a8878ab0
PPC Power PC Platform:
SuSE-7.3
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n3/radiusd-cistron-1.6.4-95.ppc.…
a541869da6cfa45822887dc69f7730f8
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/radiusd-cistron-1.6.4-95.src…
da491549cda05ead01d2dd0519f14eeb
SuSE-7.1
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n3/radiusd-cistron-1.6.4-95.ppc.…
998f87b937ec36e55ee0151f82a071fa
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/zq1/radiusd-cistron-1.6.4-95.src…
ebb96d0b9b5093a5324c90743f7a69a3
SuSE-7.0
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n2/cistron-1.6.3-85.ppc.rpm
7258462a504e594f07433f342b0870c1
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/zq1/cistron-1.6.3-85.src.rpm
d6ebb9cdd5c3538eae2db805f6fda97b
SuSE-6.4
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/n2/cistron-1.6.2-21.ppc.rpm
6274908e60a8ff24a3be7c4936b36d90
source rpm:
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/zq1/cistron-1.6.2-21.src.rpm
aa350c9fedc384c382744b4b2563250c
______________________________________________________________________________
2) Pending vulnerabilities in SuSE Distributions and Workarounds:
- mtr
A buffer overflow was found in mtr, which enables an attacker
to get access to mtr's raw socket. Fixed RPM packages are
available from our ftp servers. Additionally you should
remove the setuid bit from mtr and add an appropriate entry
in /etc/permissions.local.
- webalizer
A possible buffer overflow in the webalizer DNS resolv code
was found. The bug seems no to be exploitable. The SuSE Security
Team fixed this and other possible bugs in the webalizer code.
New RPM packages will be available on our FTP servers.
- ntop
Version < 2.0.99 of ntop could be crashed by feeding ntop's HTTP
code with invalid URL's. This bug does not exist in ntop version 2.0.1
which is shipped with SuSE 8.0.
- slrnpull
Problems with slrnpull have been reported on the bugtraq mailinglist.
SuSE does not ship this program setuid and is therefore not vulnerable
to the buffer overflow attack against this program.
- openssh
Niels Provos published a local exploitable bug for OpenSSH.
This bug could only be exploited if Kerberos and AFS support was
enabled while compiling OpenSSH. The OpenSSH RPM file that comes with
SuSE hasn't enabled Kerberos nor AFS, so we are not vulnerable to this
attack. The bug will be fixed with the next security update of OpenSSH.
______________________________________________________________________________
3) standard appendix: authenticity verification, additional information
- Package authenticity verification:
SuSE update packages are available on many mirror ftp servers all over
the world. While this service is being considered valuable and important
to the free and open source software community, many users wish to be
sure about the origin of the package and its content before installing
the package. There are two verification methods that can be used
independently from each other to prove the authenticity of a downloaded
file or rpm package:
1) md5sums as provided in the (cryptographically signed) announcement.
2) using the internal gpg signatures of the rpm package.
1) execute the command
md5sum <name-of-the-file.rpm>
after you downloaded the file from a SuSE ftp server or its mirrors.
Then, compare the resulting md5sum with the one that is listed in the
announcement. Since the announcement containing the checksums is
cryptographically signed (usually using the key security(a)suse.de)
the checksums show proof of the authenticity of the package.
We disrecommend to subscribe to security lists which cause the
email message containing the announcement to be modified so that
the signature does not match after transport through the mailing
list software.
Downsides: You must be able to verify the authenticity of the
announcement in the first place. If RPM packages are being rebuilt
and a new version of a package is published on the ftp server, all
md5 sums for the files are useless.
2) rpm package signatures provide an easy way to verify the authenticity
of an rpm package. Use the command
rpm -v --checksig <file.rpm>
to verify the signature of the package, where <file.rpm> is the
filename of the rpm package that you have downloaded. Of course,
package authenticity verification can only target an uninstalled rpm
package file.
Prerequisites:
a) gpg is installed
b) The package is signed using a certain key. The public part of this
key must be installed by the gpg program in the directory
~/.gnupg/ under the user's home directory who performs the
signature verification (usually root). You can import the key
that is used by SuSE in rpm packages for SuSE Linux by saving
this announcement to a file ("announcement.txt") and
running the command (do "su -" to be root):
gpg --batch; gpg < announcement.txt | gpg --import
SuSE Linux distributions version 7.1 and thereafter install the
key "build(a)suse.de" upon installation or upgrade, provided that
the package gpg is installed. The file containing the public key
is placed at the toplevel directory of the first CD (pubring.gpg)
and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de .
- SuSE runs two security mailing lists to which any interested party may
subscribe:
suse-security(a)suse.com
- general/linux/SuSE security discussion.
All SuSE security announcements are sent to this list.
To subscribe, send an email to
<suse-security-subscribe(a)suse.com>.
suse-security-announce(a)suse.com
- SuSE's announce-only mailing list.
Only SuSE's security annoucements are sent to this list.
To subscribe, send an email to
<suse-security-announce-subscribe(a)suse.com>.
For general information or the frequently asked questions (faq)
send mail to:
<suse-security-info(a)suse.com> or
<suse-security-faq(a)suse.com> respectively.
=====================================================================
SuSE's security contact is <security(a)suse.com> or <security(a)suse.de>.
The <security(a)suse.de> public key is listed below.
=====================================================================
______________________________________________________________________________
The information in this advisory may be distributed or reproduced,
provided that the advisory is not modified in any way. In particular,
it is desired that the cleartext signature shows proof of the
authenticity of the text.
SuSE GmbH makes no warranties of any kind whatsoever with respect
to the information contained in this security advisory.
Type Bits/KeyID Date User ID
pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security(a)suse.de>
pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build(a)suse.de>
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff
4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d
M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO
QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK
XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE
D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd
G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM
CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE
myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr
YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD
wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d
NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe
QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe
LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t
XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU
D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3
0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot
1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW
cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E
ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f
AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E
Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/
HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h
t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT
tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM
523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q
2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8
QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw
JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ
1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH
ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1
wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY
EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol
0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK
CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co
SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo
omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt
A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J
/LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE
GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf
ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8
RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ
8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb
B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X
11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA
8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj
qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p
WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL
hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG
BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+
AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi
RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0
zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM
/3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7
whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl
D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz
dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI
RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI
DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=
=LRKC
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
iQEVAwUBPM0xTXey5gA9JdPZAQGrKgf/U+sVMw2IG/AB0fCZLuFHxWeUPf1ivvYN
7HwFYivB2LQgQGpPRT/T9YpdsnRJzCIugyx+sMFDjN6ARGRpeehQR5P+OZPq0xBH
ptxcfks4/1u3bx/pRQ5a4KOxqSscYuEL8B66yH4nTb2E5QsmR5ZCxtoA0VtwLFT2
ZGqr3eAY6Uk78V7G/oPszdZtkcPJGMsHg6TEjFiu5ff7pclULWSmj8iQBKcMJbcG
sFu3kfhrGYDq0MYMLTXttDDgC7dM9Y4z819ZHDZA2cSZAiBEuCFQ+NweEE4+sY/r
QDie2nbRr6ZWTLYz6/kUc5KNyhMiQD+qhkUJg5yhDBnb/BFu7yfahg==
=APbN
-----END PGP SIGNATURE-----
--
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer(a)suse.de - SuSE Security Team
~
1
0