|
Gentoo: bladeenc arbitrary code execution |
|
|
|
Posted by LinuxSecurity.com Team
|
A wave file will let the attacker to execute all the code he wants on the victim.
- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200302-04
- --------------------------------------------------------------------
PACKAGE : bladeenc
SUMMARY : arbitrary code execution
DATE : 2003-02-05 12:55 UTC
EXPLOIT : local
- --------------------------------------------------------------------
From advisory:
"A wave file let the attacker to execute all the code he want on the
victim"
Read the full advisory at:
http://www.pivx.com/luigi/adv/blade942-adv.txt
SOLUTION
It is recommended that all Gentoo Linux users who are running
media-sound/bladeenc upgrade to bladeenc-0.94.2-r1 as follows:
emerge sync
emerge -u bladeenc
emerge clean
- --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
styx@gentoo.org
- --------------------------------------------------------------------
|