Setuid bits are removed on dump to prevent exploit
| Advisory: | RHSA-2000:100-02 |
|---|---|
| Type: | Security Advisory |
| Severity: | N/A |
| Issued on: | 2000-11-02 |
| Last updated on: | 2000-11-02 |
| Affected Products: | Red Hat Linux 6.2 Red Hat Linux Enterprise Edition |
| CVEs (cve.mitre.org): |
CVE-2000-0186 CVE-2000-0520 |
Details
The Red Hat 7.0 dump is being released for Red Hat 6.x and Red Hat 5.x
in order to remove root setuid bits to prevent a known dump
exploit (#20111).
The new dump packages also include a fix for a buffer overflow (#9899)
Dump can be used to gain root access.
Solution
For each RPM for your particular architecture, run:
rpm -Fvh [filename]
where filename is the name of the RPM.
rpm -Fvh [filename]
where filename is the name of the RPM.
Updated packages
| Red Hat Linux 6.2 | |
| SRPMS: | |
| dump-0.4b19-5.6x.src.rpm File outdated by: RHSA-2002:026 |
MD5: 48225b01757f79eecd50e20cc3746017 |
| Alpha: | |
| dump-0.4b19-5.6x.alpha.rpm File outdated by: RHSA-2002:026 |
MD5: 339d7bdc63a154a08ac05b2d59be299f |
| dump-static-0.4b19-5.6x.alpha.rpm File outdated by: RHSA-2002:026 |
MD5: aa4eb8d7e446cdbaf10cec1d6beb2ea8 |
| rmt-0.4b19-5.6x.alpha.rpm File outdated by: RHSA-2002:026 |
MD5: d70e961e5ce712df4b671fe7fa53cf0f |
| IA-32: | |
| dump-0.4b19-5.6x.i386.rpm File outdated by: RHSA-2002:026 |
MD5: 62d35595f6b11c7a478d2f3608ebb8b3 |
| dump-static-0.4b19-5.6x.i386.rpm File outdated by: RHSA-2002:026 |
MD5: 86a7cd33b8c870f01a4fe3fc500a6af1 |
| rmt-0.4b19-5.6x.i386.rpm File outdated by: RHSA-2002:026 |
MD5: 6f1831d60345791448f94f7e8276a47e |
| Sparc: | |
| dump-0.4b19-5.6x.sparc.rpm File outdated by: RHSA-2002:026 |
MD5: f907fe91725a340c07f44d381eb4da70 |
| dump-static-0.4b19-5.6x.sparc.rpm File outdated by: RHSA-2002:026 |
MD5: daaf188d21fdfe8141f4e0dcfc8fa51e |
| rmt-0.4b19-5.6x.sparc.rpm File outdated by: RHSA-2002:026 |
MD5: 930c7a447f5c197a73e619789a8ae18a |
Bugs fixed (see bugzilla for more information)
20111 - RH6.2 dump SUID exploit (via RSH env. var)
References
https://www.redhat.com/security/data/cve/CVE-2000-0186.html
https://www.redhat.com/security/data/cve/CVE-2000-0520.html
N/A
https://www.redhat.com/security/data/cve/CVE-2000-0520.html
N/A
Keywords
exploit
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/