Security Advisory Low: coreutils security update

Advisory: RHSA-2008:0780-3
Type: Security Advisory
Severity: Low
Issued on: 2008-07-24
Last updated on: 2008-07-24
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
OVAL: com.redhat.rhsa-20080780.xml
CVEs (cve.mitre.org): CVE-2008-1946

Details

Updated coreutils packages that fix a security issue are now available for
Red Hat Enterprise Linux 4.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

The coreutils package contains the core GNU utilities. It is the
combination of the old GNU fileutils, sh-utils, and textutils packages.

The coreutils packages were found to not use the pam_succeed_if Pluggable
Authentication Module (PAM) correctly in the configuration file for the
"su" command. Any local user could use this command to change to a locked
or expired user account if the target account's password was known to the
user running "su". These updated packages, correctly, only allow the root
user to switch to locked or expired accounts using "su". (CVE-2008-1946)

All users of coreutils are advised to upgrade to this updated package,
which resolve this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
coreutils-5.2.1-31.8.el4.src.rpm
File outdated by:  RHBA-2009:0959
    68ca947da6915df3a081eaa3eccf3afd
 
IA-32:
coreutils-5.2.1-31.8.el4.i386.rpm
File outdated by:  RHBA-2009:0959
    3dea7ca4184cd4ef2b8a8cd11f3160ac
 
x86_64:
coreutils-5.2.1-31.8.el4.x86_64.rpm
File outdated by:  RHBA-2009:0959
    36da3e3c21cb344cbff2040cc303a474
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
coreutils-5.2.1-31.8.el4.src.rpm
File outdated by:  RHBA-2009:0959
    68ca947da6915df3a081eaa3eccf3afd
 
IA-32:
coreutils-5.2.1-31.8.el4.i386.rpm
File outdated by:  RHBA-2009:0959
    3dea7ca4184cd4ef2b8a8cd11f3160ac
 
IA-64:
coreutils-5.2.1-31.8.el4.ia64.rpm
File outdated by:  RHBA-2009:0959
    b1d97287a7ba8810877301c5e1c7c7b3
 
PPC:
coreutils-5.2.1-31.8.el4.ppc.rpm
File outdated by:  RHBA-2009:0959
    b3f73218d95c5f8aec66347b56cc5e5a
 
s390:
coreutils-5.2.1-31.8.el4.s390.rpm
File outdated by:  RHBA-2009:0959
    0e2591e5c9a5b6b8402478c90eb5121f
 
s390x:
coreutils-5.2.1-31.8.el4.s390x.rpm
File outdated by:  RHBA-2009:0959
    79cc42e1a2830a5ea88f2a78d242c484
 
x86_64:
coreutils-5.2.1-31.8.el4.x86_64.rpm
File outdated by:  RHBA-2009:0959
    36da3e3c21cb344cbff2040cc303a474
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
coreutils-5.2.1-31.8.el4.src.rpm
File outdated by:  RHBA-2009:0959
    68ca947da6915df3a081eaa3eccf3afd
 
IA-32:
coreutils-5.2.1-31.8.el4.i386.rpm
File outdated by:  RHBA-2009:0959
    3dea7ca4184cd4ef2b8a8cd11f3160ac
 
IA-64:
coreutils-5.2.1-31.8.el4.ia64.rpm
File outdated by:  RHBA-2009:0959
    b1d97287a7ba8810877301c5e1c7c7b3
 
x86_64:
coreutils-5.2.1-31.8.el4.x86_64.rpm
File outdated by:  RHBA-2009:0959
    36da3e3c21cb344cbff2040cc303a474
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
coreutils-5.2.1-31.8.el4.src.rpm
File outdated by:  RHBA-2009:0959
    68ca947da6915df3a081eaa3eccf3afd
 
IA-32:
coreutils-5.2.1-31.8.el4.i386.rpm
File outdated by:  RHBA-2009:0959
    3dea7ca4184cd4ef2b8a8cd11f3160ac
 
IA-64:
coreutils-5.2.1-31.8.el4.ia64.rpm
File outdated by:  RHBA-2009:0959
    b1d97287a7ba8810877301c5e1c7c7b3
 
x86_64:
coreutils-5.2.1-31.8.el4.x86_64.rpm
File outdated by:  RHBA-2009:0959
    36da3e3c21cb344cbff2040cc303a474
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

446488 - CVE-2008-1946 /etc/pam.d/su is wrong in RHEL-4.6


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/