Hi, will be there an update by SuSE? Or is ~> rpm -q htdig htdig-3.1.2-28 not affected? Tobias http://lwn.net/daily/htdig-hole.html
Date: Fri, 25 Feb 2000 18:52:44 -0600 To: lwn@lwn.net From: Geoff Hutchison <ghutchis@wso.williams.edu> Subject: [SECURITY] Security hole in ht://Dig's htsearch
(What follows was sent to the htdig, htdig3-announce and htdig3-dev mailing lists earlier today.)
Hi,
I'm sending this message out essentially twice. The contents are included in the ht://Dig 3.1.5 release notes at <http://www.htdig.org/RELEASE.html>;, but I wanted to make sure everyone got the message. There is a security hole in all versions of the htsearch CGI prior to version 3.1.5 (just released).
This hole can allow remote users to read any file on your system that the UID running your webserver can read.
It is *strongly* recommended that you upgrade to 3.1.5 ASAP. Anyone upgrading from a 3.1.x stable release will find the process fairly painless and to fix the hole, they can simply drop in the new CGI. The databases themselves are not affected. You may also wish to look at the new default templates as they make use of new features and generate cleaner HTML output.
Anyone using version 3.2.0b1 is suggested to upgrade to the latest development snapshot. The next beta version, 3.2.0b2, will be released shortly to address this issue and other bugs.
More detailed information will be posted to the BugTraq mailing list in a day or two.
-Geoff Hutchison Williams Students Online http://wso.williams.edu/
Hi,
will be there an update by SuSE? Or is ~> rpm -q htdig htdig-3.1.2-28 not affected?
we will provide a fixed RPM asap... Bye, Thomas -- Thomas Biege, SuSE GmbH, Schanzaeckerstr. 10, 90443 Nuernberg E@mail: thomas@suse.de Function: Security Support & Auditing "lynx -source http://www.suse.de/~thomas/thomas.pgp | pgp -fka" Key fingerprint = 09 48 F2 FD 81 F7 E7 98 6D C7 36 F1 96 6A 12 47
On Wed, 1 Mar 2000, Tobias Burnus wrote:
Hi,
we will provide a fixed RPM asap... Thanks: ftp://ftp.suse.com/pub/suse/i386/update/6.3/n1/ (and probably also for different platforms and suse versions)
Now I only miss an anouncement.
hehe, give me some time to release it. ;)
Tobias :-)
--------------------------------------------------------------------- To unsubscribe, e-mail: suse-security-unsubscribe@suse.com For additional commands, e-mail: suse-security-help@suse.com
Bye, Thomas -- Thomas Biege, SuSE GmbH, Schanzaeckerstr. 10, 90443 Nuernberg E@mail: thomas@suse.de Function: Security Support & Auditing "lynx -source http://www.suse.de/~thomas/thomas.pgp | pgp -fka" Key fingerprint = 09 48 F2 FD 81 F7 E7 98 6D C7 36 F1 96 6A 12 47
participants (2)
-
Thomas Biege
-
Tobias Burnus