- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200307-01
- - - ---------------------------------------------------------------------

          PACKAGE : mikmod
          SUMMARY : buffer overflow
             DATE : 2003-07-02 21:27 UTC
          EXPLOIT : local
VERSIONS AFFECTED : =mikmod-3.1.6a
              CVE : CAN-2003-0427

- - - ---------------------------------------------------------------------

quote from cve:
"Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to 
execute arbitrary code via an archive file that contains a file with a 
long filename."

SOLUTION

It is recommended that all Gentoo Linux users who are running
media-sound/mikmod upgrade to mikmod-3.1.6a as follows

emerge sync
emerge mikmod
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - - ---------------------------------------------------------------------

Gentoo: mikmod arbitrary code execution vulnerability

Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200307-01


quote from cve: "Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename."
SOLUTION
It is recommended that all Gentoo Linux users who are running media-sound/mikmod upgrade to mikmod-3.1.6a as follows
emerge sync emerge mikmod emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

Concerns

Severity
PACKAGE : mikmod
SUMMARY : buffer overflow
DATE : 2003-07-02 21:27 UTC
EXPLOIT : local
VERSIONS AFFECTED : =mikmod-3.1.6a
CVE : CAN-2003-0427

Synopsis

Background

Affected Packages

Impact

Workaround

Related News