Security Advisory Updated mailx and perl packages are now available.

Advisory: RHSA-2000:048-07
Type: Security Advisory
Severity: N/A
Issued on: 2000-08-07
Last updated on: 2001-02-25
Affected Products: Red Hat Linux 6.2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2000-0703

Details

Updated perl and mailx package are now available which fix a potential
exploit made possible by incorrect assumptions made in suidperl.

This advisory contains additional instructions for installing the necessary
updates.

Under certain conditions, suidperl will attempt to send mail to the local
superuser account using /bin/mail. A properly formatted exploit script can
use this facility, along with mailx's tendency to inherit settings from the
environment, to gain local root access.

This update changes suidperl's behavior to use syslog instead of mail, and
restricts the list of variables /bin/mail will read from the environment.


Solution

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.

In order to install some of these packages, you may need to have a newer
version of RPM installed. Information about obtaining the new version of
RPM is included in RHSA-2000:051.

Updated packages

Red Hat Linux 6.2

alpha:
ftp://updates.redhat.com/6.2/alpha/perl-5.00503-12.alpha.rpm
Missing file
    a427968de08a254dfb453d20d7c1637f
 
i386:
ftp://updates.redhat.com/6.2/i386/perl-5.00503-12.i386.rpm
Missing file
    a7fd33fe3375b27197f184e9ad8d3c15
 
sparc:
ftp://updates.redhat.com/6.2/sparc/perl-5.00503-12.sparc.rpm
Missing file
    fbd5a523fbfc8103792368317753cf35
 

Bugs fixed (see bugzilla for more information)

15641 - suidperl has a major problem


References


Keywords

rpm


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/