Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5650-1] util-linux security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5650-1] util-linux security update


Chronologisch Thread  
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5650-1] util-linux security update
  • Date: Sun, 31 Mar 2024 11:49:36 +0000
  • List-archive: https://lists.debian.org/msgid-search/E1rqtgu-008BVz-L6 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=FApzQHXrNSD+SB8lWHu/O+3FPM0iF8qHDd0bXx4AlnU=; b=hJ exDE56a2LKUalVDR78gJT59DY/kOaOZNB65wNgzC1pT70c7sH8CxwuNOFuhOcEFgUnmDVdiNTmm96 4g4qpWCfC67kMDhvb2iq+gTpt0E6hvL4z58NzHQIhGo3QfEjLs9FrxZ3Te+wNHmBjeLgljQ1lybMl Sxk7V4Qe4s4i6vyZVr0Z//A9fqi+rKQbc8QvF+E7EBNZrZUlfYN3ufDvUgUs1x/isboy4ivoWst4f JnprMJHmA/VjzTG1SYTd2t9CHOwGodEkKhLc+g5Qlgb4rXvlQVM6vFwuOM+pTbK+Xk7mF421/oTJW LEwaYOEOBujZTleiR07LKJuRZZAUpOVQ==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 31 Mar 2024 11:50:05 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <iMGqIhkhaWO.A.gVB.t3UCmB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5650-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
March 31, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : util-linux
CVE ID : CVE-2024-28085
Debian Bug : 1067849

Skyler Ferrante discovered that the wall tool from util-linux does not
properly handle escape sequences from command line arguments. A local
attacker can take advantage of this flaw for information disclosure.

With this update wall and write are not anymore installed with setgid
tty.

For the oldstable distribution (bullseye), this problem has been fixed
in version 2.36.1-8+deb11u2.

For the stable distribution (bookworm), this problem has been fixed in
version 2.38.1-5+deb12u1.

We recommend that you upgrade your util-linux packages.

For the detailed security status of util-linux please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/util-linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmYJTYpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Sm+A//cJhy/p0UGnSP5MYNc1a1sLeAMcNJm4lwxqR3zDYYqPWAe0jwsspaguNY
1QPdaqa3d/Vm8pDO8WCnqxuzwqDjwyKNLUYmFbOyDx+U4EyVxC6wsUq936XMvx/5
xiuTJripQm8urnvCaa7lGLhNSWHOc2jHWCqLnXC2AKwAtSGT7LWFKzC8csHxtRYO
5A5iUaDONPWJtGpNDx1cczfIuEUvGpANQWOgxrcyAmHb1kjpGHm0RTikpkqKNm4W
VH+DbgzuXlLtzUn0/YUXJPJkZtPe1LDshhUwFhU13K2lIUk3hWBWyGIrXgG+OZhu
XgPc/5yAZHjmffHawUPE0LWGA3U6xOWV3pvBIi07XF/kFwR00PXGfMdv9WrTUxxV
V6Fv5/kd2MsWvZQSYJ9Bn/6Wo5O9w8M3Lfso2OYx01OFRQHQfn4rfRek0ED81155
qqPaemJYeUIJsDEmiwdr+eh0LZm7+3oMOgdfKDc9ARm9fasWxA7SFg4w5P1h0IWO
lzuwEzm2W0az9YJ/BFMaZfoTTn/DW9FJHL7Fo5F2vO9CLAihxMYUDM3mUZNBexY8
Z6XzhdWOSkOAiYI4khDK/TK8jQxSpEjNiFh7Z2pIZs4F6COjI94xtIn+N5nyJxnk
AweXW0GGSZxt1sXD99JeD27Rv0UXNKyHfcQRPaYo9FyHntkVxi4=
=jL1I
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5650-1] util-linux security update, Salvatore Bonaccorso, 31.03.2024

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang