「/../」などといったディレクトリ トラバーサル シーケンスを含んだデバイス名を許していたUtempterの欠陥をSteve Grubb氏が発見しました。utmpファイルやwtmpファイルを信用しているアプリケーションと組み合わせると、この欠陥によりローカルの攻撃者がsymlinkを使用して特権つきのファイルを上書きできてしまう可能性があります。
| Red Hat Desktop (v. 3) |
|
| AMD64: |
| utempter-0.5.5-1.3EL.0.x86_64.rpm |
39e382c6a8e6a1ec5e05c5ba9bad4ee8 |
| |
| SRPMS: |
| utempter-0.5.5-1.3EL.0.src.rpm |
bb78ec4f0201e337eca2a0da85d5aa3d |
| |
| i386: |
| utempter-0.5.5-1.3EL.0.i386.rpm |
437cbd0cf70f4c106d8769022818046e |
| |
| Red Hat Enterprise Linux AS (v. 2.1) |
|
| SRPMS: |
| utempter-0.5.5-1.2.1EL.0.src.rpm |
bfcd383f81642909da3b591dc501ea26 |
| |
| i386: |
| utempter-0.5.5-1.2.1EL.0.i386.rpm |
417fb9a00960adc60d2480e76a1432e9 |
| |
| ia64: |
| utempter-0.5.5-1.2.1EL.0.ia64.rpm |
36023598fdb8c619e3a7ddf3071eeda8 |
| |
| Red Hat Enterprise Linux AS (v. 3) |
|
| AMD64: |
| utempter-0.5.5-1.3EL.0.x86_64.rpm |
39e382c6a8e6a1ec5e05c5ba9bad4ee8 |
| |
| SRPMS: |
| utempter-0.5.5-1.3EL.0.src.rpm |
bb78ec4f0201e337eca2a0da85d5aa3d |
| |
| i386: |
| utempter-0.5.5-1.3EL.0.i386.rpm |
437cbd0cf70f4c106d8769022818046e |
| |
| ia64: |
| utempter-0.5.5-1.3EL.0.ia64.rpm |
78a2997b4bfa09e8797aa8168db5ee99 |
| |
| ppc: |
| utempter-0.5.5-1.3EL.0.ppc.rpm |
fa912c642528d6d1785245c0bed610a3 |
| |
| s390: |
| utempter-0.5.5-1.3EL.0.s390.rpm |
d6bd211838e75ae01eed0ad10f638fae |
| |
| s390x: |
| utempter-0.5.5-1.3EL.0.s390x.rpm |
95518a64083b9610d6d13d01991296cf |
| |
| Red Hat Enterprise Linux ES (v. 2.1) |
|
| SRPMS: |
| utempter-0.5.5-1.2.1EL.0.src.rpm |
bfcd383f81642909da3b591dc501ea26 |
| |
| i386: |
| utempter-0.5.5-1.2.1EL.0.i386.rpm |
417fb9a00960adc60d2480e76a1432e9 |
| |
| Red Hat Enterprise Linux ES (v. 3) |
|
| AMD64: |
| utempter-0.5.5-1.3EL.0.x86_64.rpm |
39e382c6a8e6a1ec5e05c5ba9bad4ee8 |
| |
| SRPMS: |
| utempter-0.5.5-1.3EL.0.src.rpm |
bb78ec4f0201e337eca2a0da85d5aa3d |
| |
| i386: |
| utempter-0.5.5-1.3EL.0.i386.rpm |
437cbd0cf70f4c106d8769022818046e |
| |
| ia64: |
| utempter-0.5.5-1.3EL.0.ia64.rpm |
78a2997b4bfa09e8797aa8168db5ee99 |
| |
| Red Hat Enterprise Linux WS (v. 2.1) |
|
| SRPMS: |
| utempter-0.5.5-1.2.1EL.0.src.rpm |
bfcd383f81642909da3b591dc501ea26 |
| |
| i386: |
| utempter-0.5.5-1.2.1EL.0.i386.rpm |
417fb9a00960adc60d2480e76a1432e9 |
| |
| Red Hat Enterprise Linux WS (v. 3) |
|
| AMD64: |
| utempter-0.5.5-1.3EL.0.x86_64.rpm |
39e382c6a8e6a1ec5e05c5ba9bad4ee8 |
| |
| SRPMS: |
| utempter-0.5.5-1.3EL.0.src.rpm |
bb78ec4f0201e337eca2a0da85d5aa3d |
| |
| i386: |
| utempter-0.5.5-1.3EL.0.i386.rpm |
437cbd0cf70f4c106d8769022818046e |
| |
| ia64: |
| utempter-0.5.5-1.3EL.0.ia64.rpm |
78a2997b4bfa09e8797aa8168db5ee99 |
| |
| Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor |
|
| SRPMS: |
| utempter-0.5.5-1.2.1EL.0.src.rpm |
bfcd383f81642909da3b591dc501ea26 |
| |
| ia64: |
| utempter-0.5.5-1.2.1EL.0.ia64.rpm |
36023598fdb8c619e3a7ddf3071eeda8 |
| |
(The unlinked packages above are only available from the Red Hat Network)
|