6423425 2001-04-27 13:53 -0700  /66 rader/ Greg KH <greg@WIREX.COM>
Sänt av: joel@lysator.liu.se
Importerad: 2001-04-28  02:26  av Brevbäraren
Extern mottagare: BUGTRAQ@SECURITYFOCUS.COM
Externa svar till: greg@WIREX.COM
Mottagare: Bugtraq (import) <16826>
Ärende: Immunix OS Security update for gftp
------------------------------------------------------------
-----------------------------------------------------------------------
	Immunix OS Security Advisory

Packages updated:	gftp
Affected products:	Immunix OS 6.2, 7.0-beta, and 7.0
Bugs Fixed:		immunix/1578
Date:			April 27, 2001
Advisory ID:		IMNX-2001-70-017-01
Author:			Greg Kroah-Hartman <greg@wirex.com>
-----------------------------------------------------------------------

Description:
  Richard Johnson has found a format string problem in the version of
  gftp that ships with Immunix 6.2 and 7.0 (for more information, please
  see http://www.securityfocus.com/archive/82/177241 )

  Normally, printf-style format bugs like this one would be stopped
  by FormatGuard, but FormatGuard is only effective at protecting
  applications that use the printf-like family of functions found in
  glibc.  gftp uses string formatting functions found in GLib (the
  GTK+ library, *not* glibc) which bypass FormatGuard protection.

  The following packages fix this problem.


Package names and locations:

  Precompiled binary package for Immunix 6.2 is available at:
    http://immunix.org/ImmunixOS/6.2/updates/RPMS/gftp-2.0.8-1_StackGuard.i386.rpm

  Source package for Immunix 6.2 is available at:
    http://immunix.org/ImmunixOS/6.2/updates/SRPMS/gftp-2.0.8-1_StackGuard.src.rpm

  Precompiled binary package for Immunix 7.0-beta and 7.0 is available at:
    http://immunix.org/ImmunixOS/7.0/updates/RPMS/gftp-2.0.8-1_imnx.i386.rpm

  Source package for Immunix 7.0-beta and 7.0 is available at:
    http://immunix.org/ImmunixOS/7.0/updates/SRPMS/gftp-2.0.8-1_imnx.src.rpm


md5sums of the packages:
  21ed7aec4ce92054a9d7b74144b677eb  gftp-2.0.8-1_StackGuard.i386.rpm
  ec85dc5cf7f5a27387390039e152e78a  gftp-2.0.8-1_StackGuard.src.rpm

  b9f4ee8b9b4bce6f8091040860dfd9da  gftp-2.0.8-1_imnx.i386.rpm
  282406a684ae7f546388a03c8491d3d8  gftp-2.0.8-1_imnx.src.rpm


Online version of all Immunix 6.2 updates and advisories:
  http://immunix.org/ImmunixOS/6.2/updates/

Online version of all Immunix 7.0-beta updates and advisories:
  http://immunix.org/ImmunixOS/7.0-beta/updates/

Online version of all Immunix 7.0 updates and advisories:
  http://immunix.org/ImmunixOS/7.0/updates/

NOTE:
  Ibiblio is graciously mirroring our updates, so if the links above are
  slow, please try:
    ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/
  or one of the many mirrors available at:
    http://www.ibiblio.org/pub/Linux/MIRRORS.html
(6423425) /Greg KH <greg@WIREX.COM>/------(Ombruten)
Bilaga (application/pgp-signature) i text 6423426
6423426 2001-04-27 13:53 -0700  /10 rader/ Greg KH <greg@WIREX.COM>
Importerad: 2001-04-28  02:26  av Brevbäraren
Extern mottagare: BUGTRAQ@SECURITYFOCUS.COM
Externa svar till: greg@WIREX.COM
Mottagare: Bugtraq (import) <16827>
Bilaga (text/plain) till text 6423425
Ärende: Bilaga till: Immunix OS Security update for gftp
------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE66dxhAl5ylTeuKpURArTaAJ4s/IHrMSP0z1V3Xht7M8XXOKQ6ogCfezfr
O7KK3I9TlH6UX+/hJVE/19Q=
=7ScK
-----END PGP SIGNATURE-----
(6423426) /Greg KH <greg@WIREX.COM>/----------------