From 9d6a7d2dfd3762e08d75f45576abaf135df74b4a Mon Sep 17 00:00:00 2001 From: Micah Anderson Date: Thu, 15 Sep 2005 23:03:31 +0000 Subject: Moving kdelibs up so i can release lm-sensors git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@2009 e39458fd-73e7-0310-bf30-c45bca0a0e42 --- data/DTSA/advs/17-kdelibs.adv | 15 --------------- data/DTSA/advs/17-lm-sensors.adv | 19 +++++++++++++++++++ data/DTSA/advs/18-kdelibs.adv | 15 +++++++++++++++ data/DTSA/advs/18-lm-sensors.adv | 19 ------------------- 4 files changed, 34 insertions(+), 34 deletions(-) delete mode 100644 data/DTSA/advs/17-kdelibs.adv create mode 100644 data/DTSA/advs/17-lm-sensors.adv create mode 100644 data/DTSA/advs/18-kdelibs.adv delete mode 100644 data/DTSA/advs/18-lm-sensors.adv (limited to 'data/DTSA/advs') diff --git a/data/DTSA/advs/17-kdelibs.adv b/data/DTSA/advs/17-kdelibs.adv deleted file mode 100644 index 4b12cbd030..0000000000 --- a/data/DTSA/advs/17-kdelibs.adv +++ /dev/null @@ -1,15 +0,0 @@ -source: kdelibs -date: September 13th, 2005 -author: Moritz Muehlenhoff -vuln-type: insecure default permissions -problem-scope: local -debian-specifc: no -cve: CAN-2005-1920 -vendor-advisory: -testing-fix: 4:3.3.2-6.1etch1 -sid-fix: 4:3.4.2-1 -upgrade: apt-get install kdelibs4 - -kate always created backup files for edited files with default permissions, -even if the original permissions were stricter. This could lead to information -disclosure. \ No newline at end of file diff --git a/data/DTSA/advs/17-lm-sensors.adv b/data/DTSA/advs/17-lm-sensors.adv new file mode 100644 index 0000000000..f496864618 --- /dev/null +++ b/data/DTSA/advs/17-lm-sensors.adv @@ -0,0 +1,19 @@ +source: lm-sensors +date: September 15th, 2005 +author: Micah Anderson +vuln-type: insecure temporary file +problem-scope: local +debian-specifc: no +cve: CAN-2005-2672 +vendor-advisory: +testing-fix: lm-sensors_1:2.9.1-6etch1 +sid-fix: 1:2.9.1-7 +upgrade: apt-get install lm-sensors + +Javier Fernández-Sanguino Peña discovered that a script included in +lm-sensors, used to read temperature/voltage/fan sensors, creates a temporary +file with a predictable filename, leaving it vulnerable for a symlink +attack. + +Note that this is the same set of security fixes put into stable in +DSA-814-1. diff --git a/data/DTSA/advs/18-kdelibs.adv b/data/DTSA/advs/18-kdelibs.adv new file mode 100644 index 0000000000..4b12cbd030 --- /dev/null +++ b/data/DTSA/advs/18-kdelibs.adv @@ -0,0 +1,15 @@ +source: kdelibs +date: September 13th, 2005 +author: Moritz Muehlenhoff +vuln-type: insecure default permissions +problem-scope: local +debian-specifc: no +cve: CAN-2005-1920 +vendor-advisory: +testing-fix: 4:3.3.2-6.1etch1 +sid-fix: 4:3.4.2-1 +upgrade: apt-get install kdelibs4 + +kate always created backup files for edited files with default permissions, +even if the original permissions were stricter. This could lead to information +disclosure. \ No newline at end of file diff --git a/data/DTSA/advs/18-lm-sensors.adv b/data/DTSA/advs/18-lm-sensors.adv deleted file mode 100644 index f496864618..0000000000 --- a/data/DTSA/advs/18-lm-sensors.adv +++ /dev/null @@ -1,19 +0,0 @@ -source: lm-sensors -date: September 15th, 2005 -author: Micah Anderson -vuln-type: insecure temporary file -problem-scope: local -debian-specifc: no -cve: CAN-2005-2672 -vendor-advisory: -testing-fix: lm-sensors_1:2.9.1-6etch1 -sid-fix: 1:2.9.1-7 -upgrade: apt-get install lm-sensors - -Javier Fernández-Sanguino Peña discovered that a script included in -lm-sensors, used to read temperature/voltage/fan sensors, creates a temporary -file with a predictable filename, leaving it vulnerable for a symlink -attack. - -Note that this is the same set of security fixes put into stable in -DSA-814-1. -- cgit v1.2.3