rPath Security Advisory: 2007-0004-1
Published: 2007-01-09
Products: rPath Linux 1
Rating: Minor
Exposure Level Classification:
Local Non-deterministic Unauthorized Access
Updated Versions:
bzip2=/suppressed:devel//1/1.0.4-1-0.1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0953
https://issues.rpath.com/browse/RPL-921
Description:
Previous versions of the bzip2 package are vulnerable to a race
condition that allows local users to modify permissions on
arbitrary files that the user running bzip2 is allowed to change.
Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.