Security Advisory Updated diffutils packages available

Advisory: RHSA-2001:116-03
Type: Security Advisory
Severity: N/A
Issued on: 2001-10-03
Last updated on: 2001-10-17
Affected Products: Red Hat Linux 5.2
Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
OVAL: N/A
CVEs (cve.mitre.org): CVE-2001-0117

Details

Updated diffutils packages are now available, fixing a temporary file
handling vulnerability in the sdiff program.

When using sdiff in interactive mode, a temporary file is created. The
new diffutils packages make sure to create that file in a secure way.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 5.2

SRPMS:
ftp://updates.redhat.com/5.2/en/os/SRPMS/diffutils-2.7-22.5x.src.rpm
Missing file
    ff7029002d184b7b860f21524f696b60
 
alpha:
ftp://updates.redhat.com/5.2/en/os/alpha/diffutils-2.7-22.5x.alpha.rpm
Missing file
    35dfb8e4aba080dcbda65519bf266b71
 
i386:
ftp://updates.redhat.com/5.2/en/os/i386/diffutils-2.7-22.5x.i386.rpm
Missing file
    729984eac74f725e0ec8560c7ff114a5
 
sparc:
ftp://updates.redhat.com/5.2/en/os/sparc/diffutils-2.7-22.5x.sparc.rpm
Missing file
    2c7f2ab3e5c0ddeba0b1791476cb7689
 
Red Hat Linux 6.2

SRPMS:
ftp://updates.redhat.com/6.2/en/os/SRPMS/diffutils-2.7-22.6x.src.rpm
Missing file
    d736703adc89c9ec4b6b43849a93375c
 
Alpha:
ftp://updates.redhat.com/6.2/en/os/alpha/diffutils-2.7-22.6x.alpha.rpm
Missing file
    e3ebbf9aa5f5b663b011d1087866e959
 
IA-32:
ftp://updates.redhat.com/6.2/en/os/i386/diffutils-2.7-22.6x.i386.rpm
Missing file
    97f2748d9d8121b9a365c5d6e806e90f
 
Sparc:
ftp://updates.redhat.com/6.2/en/os/sparc/diffutils-2.7-22.6x.sparc.rpm
Missing file
    0689c3190111d4bbc7e37ae2da8afb7b
 
Red Hat Linux 7.0

SRPMS:
ftp://updates.redhat.com/7.0/en/os/SRPMS/diffutils-2.7-22.70.src.rpm
Missing file
    b59486f536fb05fcbb46ddf1134ad441
 
Alpha:
ftp://updates.redhat.com/7.0/en/os/alpha/diffutils-2.7-22.70.alpha.rpm
Missing file
    7220cfb847ac459e89f95163443dc4f4
 
IA-32:
ftp://updates.redhat.com/7.0/en/os/i386/diffutils-2.7-22.70.i386.rpm
Missing file
    5a826dc3cf47c95aaa1506af652c3f95
 
Red Hat Linux 7.1

SRPMS:
ftp://updates.redhat.com/7.1/en/os/SRPMS/diffutils-2.7-23.src.rpm
Missing file
    a9e358e11d2c008fe0388b69901c4533
 
Alpha:
ftp://updates.redhat.com/7.1/en/os/alpha/diffutils-2.7-23.alpha.rpm
Missing file
    687c37a41d49b288a8bcea8469837fb8
 
IA-32:
ftp://updates.redhat.com/7.1/en/os/i386/diffutils-2.7-23.i386.rpm
Missing file
    0c7ef980105572472a6ae07f13aa7e10
 
IA-64:
ftp://updates.redhat.com/7.1/en/os/ia64/diffutils-2.7-23.ia64.rpm
Missing file
    062bf0083809452267d49d42aa85d7e2
 

References


Keywords

file, sdiff, temporary


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/