[18598] in bugtraq

home help back first fref pref prev next nref lref last post

Trustix Security Advisory - diffutils squid

daemon@ATHENA.MIT.EDU (Trustix Secure Linux Team)
Fri Jan 12 18:20:46 2001

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <038zogyeil.fsf@colargol.tihlde.hist.no>
Date:         Fri, 12 Jan 2001 16:30:10 +0100
Reply-To: Trustix Secure Linux Team <tsl@TRUSTIX.COM>
From: Trustix Secure Linux Team <tsl@TRUSTIX.COM>
X-To:         tsl-announce@trustix.com
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <03ae9t7n4y.fsf@colargol.tihlde.hist.no>

Hi

Trustix today released updated versions of the diffutils and squid
packages with patches fixing insecure tempfile handling leading to
potential local root compromise.

All versions of Trustix Secure Linux are, as far as we know, vulnerable
and should be updated.

MD5sums:
1.2:
1eb251233e977a05af437e9bff2724ac  diffutils-2.7-18tr.i586.rpm
494d5139f8ae7dbfee65bc5d590de47e  squid-2.3.STABLE4-3tr.i586.rpm

1.1:
843a08cbe2a02b7a3a9c5495c2a005bf  diffutils-2.7-18tr.i586.rpm
ef5fa6722ffae66a9fd19f9e24c2c8e9  squid-2.3.STABLE4-3tr.i586.rpm

Get these updates at:
ftp://ftp.trustix.net/pub/Trustix/updates/
http://www.trustix.net/pub/Trustix/updates/

As always, any users of 1.0x should use the update for 1.1.

As of today, users of Trustix Secure Linux 1.2 can grab our new
free-as-in-speech (GPL licenced) SoftWare UPdater (SWUP) to
automatically update packages and install new packages.

Get SWUP at:
ftp://ftp.trustix.com/pub/Trustix/software/swup/

After proper configuration, you can use 'swup --update' to automatically
download new updates.

Questions?
Check out our mailinglists:
http://www.trustix.net/support/

Trustix Security Team

home help back first fref pref prev next nref lref last post