[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[debian-users:27231] [SECURITY] [DSA 011-2] New mgetty packages for m68k and powerpc available (from debian-security-announce@lists.debian.org)



debian-security-announce@lists.debian.orgに流れたメイルによれば、
[DSA 011-1](mgettyが安全でない方法で一時ファイルを作成してしまう)の、
m68k用とPowerPC用修正版ができたそうです。

以下、アナウンスの引用です。

From: Martin Schulze <joey@xxxxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: [SECURITY] [DSA 011-2] New mgetty packages for m68k and powerpc available
Date: Tue, 6 Mar 2001 03:12:21 +0100

> - ----------------------------------------------------------------------------
> Debian Security Advisory DSA-011-2                       security@debian.org
> http://www.debian.org/security/                               Martin Schulze
> March 6, 2001
> - ----------------------------------------------------------------------------
> 
> Package        : mgetty
> Vulnerability  : insecure tempfile creation
> Debian-specific: no
> 
> In Debian Security Advisory DSA 011-1 we have reported insecure
> creation of temporary files in the mgetty package that have been
> fixed.  For details please read the main advisory.
> 
> The most recent advisory covering proftpd missed two architectures that
> were released with Debian GNU/Linux 2.2.  Therefore this advisory is
> only an addition to DSA 011-1 and only adds the relevant package for
> the Motorola 680x0 and PowerPC architecture.
> 
> We recommend you upgrade your sudo packages for m68k immediately.
> 
> wget url
> 	will fetch the file for you
> dpkg -i file.deb
>         will install the referenced file.
> 
> You may use an automated update by adding the resources from the
> footer to the proper configuration.
(中略)
> - ----------------------------------------------------------------------------
> For apt-get: deb http://security.debian.org/ stable/updates main
> For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
> Mailing list: debian-security-announce@lists.debian.org
> Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

以上です。

ところで、原文に出てくるproftpdとsudoはどう関係あるのでしょう?
…と思ったら、連続してアナウンスが出ていますね。
-- 
喜瀬“冬猫”浩@南国沖縄