| Mandriva issues security fix |
May 25, 2006
Mandriva Linux issued a security advisory for its latest edition, version 2006.0, May 24, warning that a potential problem was found in the kernel's useradd tool. Useradd is used to add a mailbox for a new user.
According to Mandriva's advisory, when the tool is used, a missing argument to the open() call results in the first permissions of the file being some random garbage found on the stack, which then could possibly be held open for reading or writing before the proper fchmod() call is executed.
Affected versions are CS3.0, MNF2.0, and 10.2, Mandriva said in the advisory.
Packages have been patched to correct this issue, Mandriva said. Mandiva subscribers can use MandrakeUpdate to upgrade the kernel automatically, the France-based company added.
Users who may be running netfilter on important servers are encouraged to upgrade to these updated kernels immediately, Mandriva said.
To update your kernel, please follow the directions located here.
Related Stories:
(Click here for further information)
|
|
|
|
|
|
|
|