Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: 202303-07 Urgent: Netwatchdog Vulnerability Exploit Notification

gentoo
Calendar Grey July 1, 2003
Dist Gentoo Esm H88
Enhance your system's security by following procedures to upgrade tcptraceroute on Gentoo, addressing the privilege escalation issue in advisory 200306-14
tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor v...

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200306-14


quote from cve:
"tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-analyzer/tcptraceroute upgrade to tcptraceroute-1.4-r1 as follows
emerge sync emerge tcptraceroute emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : tcptraceroute
SUMMARY : problems dropping root privileges
DATE : 2003-06-28 20:21 UTC
EXPLOIT : local
VERSIONS AFFECTED : =tcptraceroute-1.4
CVE : CAN-2003-0489

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here