|
|
>> Mandriva Security Update Fixes Cpio Local Buffer Overflow Vulnerability
|
Title : Mandriva Security Update Fixes Cpio Local Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-3079 CVE ID : CVE-2005-4268
Rated as : Moderate Risk 
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-12-24
|
Mandriva has released updated packages to address a vulnerability identified in Cpio. This flaw is due to a buffer overflow error when creating a cpio archive, which could allow local attackers to cause a denial of service and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
Affected Products
Mandriva Linux 10.2
Mandriva Linux 2006.0
Solution
Upgrade the affected packages :
Mandriva Linux 10.2:
b0400cb8878a93cc4e4d4326a0a46641 10.2/RPMS/cpio-2.6-3.3.102mdk.i586.rpm
ad70b46181e5a9ae2ca7ed97bb2c3853 10.2/SRPMS/cpio-2.6-3.3.102mdk.src.rpm
Mandriva Linux 10.2/X86_64:
0a7ca9d0d1de932219a76dcee4195ff8 x86_64/10.2/RPMS/cpio-2.6-3.3.102mdk.x86_64.rpm
ad70b46181e5a9ae2ca7ed97bb2c3853 x86_64/10.2/SRPMS/cpio-2.6-3.3.102mdk.src.rpm
Mandriva Linux 2006.0:
571d79d56efac2687713e63180f10049 2006.0/RPMS/cpio-2.6-5.1.20060mdk.i586.rpm
998e92b468e495d779efd10daacae3ad 2006.0/SRPMS/cpio-2.6-5.1.20060mdk.src.rpm
Mandriva Linux 2006.0/X86_64:
0bd4e5c9d85826c706232e21d3393317 x86_64/2006.0/RPMS/cpio-2.6-5.1.20060mdk.x86_64.rpm
998e92b468e495d779efd10daacae3ad x86_64/2006.0/SRPMS/cpio-2.6-5.1.20060mdk.src.rpm
References
http://www.vupen.com/english/advisories/2005/3079 http://www.frsirt.com/english/reference/3325
ChangeLog
2005-12-24 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|