|
|
|
|
| |
When Joe (Joe's Own Editor) dies due to a signal instead of a normal exit it saves a list of the files it is editing to a file called `DEADJOE' in its current directory. Unfortunately, this was done in an unsafe manner, which made 'Joe' vulnerable to a symlink attack.
We reported this vulnerability in a previous advisory. See:
Joe Editor can be used to gain access to restricted files for more information about the vulnerability. |
| |
Credit:
The information has been provided by RedHat Bugzilla, Debian security announce, Linux Mandrake Security Team and Greg KH.
|
| |
Vulnerable systems:
Red Hat Linux 5.2 - i386, Alpha, Sparc
Red Hat Linux 6.0 - i386, Alpha, Sparc
Red Hat Linux 6.1 - i386, Alpha, Sparc
Red Hat Linux 6.2 - i386, Alpha, Sparc
Red Hat Linux 6.2EE - i386
Red Hat Linux 7.0 - i386
Debian GNU/Linux 2.2 alias potato
Linux Mandrake 6.0
Linux Mandrake 6.1
Linux Mandrake 7.0
Linux Mandrake 7.1
Linux Mandrake 7.2
Immunix OS 6.2
Immunix OS 7.0-beta
Solution (RedHat):
For each RPM for your particular architecture, run:
rpm -Fvh [filename]
Where filename is the name of the RPM.
Patch:
Red Hat Linux 5.2:
Alpha:
ftp://updates.redhat.com/5.2/alpha/joe-2.8-42.52.alpha.rpm
Sparc:
ftp://updates.redhat.com/5.2/sparc/joe-2.8-42.52.sparc.rpm
i386:
ftp://updates.redhat.com/5.2/i386/joe-2.8-42.52.i386.rpm
Sources:
ftp://updates.redhat.com/5.2/SRPMS/joe-2.8-42.52.src.rpm
Red Hat Linux 6.0:
Sparc:
ftp://updates.redhat.com/6.0/sparc/joe-2.8-42.62.sparc.rpm
i386:
ftp://updates.redhat.com/6.0/i386/joe-2.8-42.62.i386.rpm
Alpha:
ftp://updates.redhat.com/6.0/alpha/joe-2.8-42.62.alpha.rpm
Sources:
ftp://updates.redhat.com/6.0/SRPMS/joe-2.8-42.62.src.rpm
Red Hat Linux 6.1:
Alpha:
ftp://updates.redhat.com/6.1/alpha/joe-2.8-42.62.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.1/sparc/joe-2.8-42.62.sparc.rpm
i386:
ftp://updates.redhat.com/6.1/i386/joe-2.8-42.62.i386.rpm
Sources:
ftp://updates.redhat.com/6.1/SRPMS/joe-2.8-42.62.src.rpm
Red Hat Linux 6.2:
alpha:
ftp://updates.redhat.com/6.2/alpha/joe-2.8-42.62.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.2/sparc/joe-2.8-42.62.sparc.rpm
i386:
ftp://updates.redhat.com/6.2/i386/joe-2.8-42.62.i386.rpm
Sources:
ftp://updates.redhat.com/6.2/SRPMS/joe-2.8-42.62.src.rpm
Red Hat Linux 7.0:
i386:
ftp://updates.redhat.com/7.0/i386/joe-2.8-43.i386.rpm
Sources:
ftp://updates.redhat.com/7.0/SRPMS/joe-2.8-43.src.rpm
Debian GNU/Linux 2.2 alias potato
Potato was released for Alpha, ARM, i386, M68k, PowerPC and Sparc.
Source archives:
http://security.debian.org/dists/stable/updates/main/source/joe_2.8-15.1.diff.gz
http://security.debian.org/dists/stable/updates/main/source/joe_2.8-15.1.dsc
http://security.debian.org/dists/stable/updates/main/source/joe_2.8.orig.tar.gz
Alpha architecture:
http://security.debian.org/dists/stable/updates/main/binary-alpha/joe_2.8-15.1_alpha.deb
ARM architecture:
http://security.debian.org/dists/stable/updates/main/binary-arm/joe_2.8-15.1_arm.deb
Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/main/binary-i386/joe_2.8-15.1_i386.deb
Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/main/binary-m68k/joe_2.8-15.1_m68k.deb
PowerPC architecture:
http://security.debian.org/dists/stable/updates/main/binary-powerpc/joe_2.8-15.1_powerpc.deb
Sun Sparc architecture:
http://security.debian.org/dists/stable/updates/main/binary-sparc/joe_2.8-15.1_sparc.deb
Mandrake:
Linux-Mandrake 6.0:
6.0/RPMS/joe-2.8-21.3mdk.i586.rpm
6.0/SRPMS/joe-2.8-21.3mdk.src.rpm
Linux-Mandrake 6.1:
6.1/RPMS/joe-2.8-21.3mdk.i586.rpm
6.1/SRPMS/joe-2.8-21.3mdk.src.rpm
Linux-Mandrake 7.0:
7.0/RPMS/joe-2.8-21.3mdk.i586.rpm
7.0/SRPMS/joe-2.8-21.3mdk.src.rpm
Linux-Mandrake 7.1:
7.1/RPMS/joe-2.8-21.2mdk.i586.rpm
7.1/SRPMS/joe-2.8-21.2mdk.src.rpm
Linux-Mandrake 7.2:
7.2/RPMS/joe-2.8-21.1mdk.i586.rpm
7.2/SRPMS/joe-2.8-21.1mdk.src.rpm
Immunix 6.2:
RPM:
http://www.immunix.org:8080/ImmunixOS/6.2/updates/RPMS/joe-2.8-42.62_StackGuard.i386.rpm
Source:
http://www.immunix.org:8080/ImmunixOS/6.2/updates/SRPMS/joe-2.8-42.62_StackGuard.src.rpm
Immunix System 7 beta:
RPM:
http://www.immunix.org:8080/ImmunixOS/7.0-beta/updates/RPMS/joe-2.8-43_StackGuard.i386.rpm
Source:
http://www.immunix.org:8080/ImmunixOS/7.0-beta/updates/SRPMS/joe-2.8-43_StackGuard.src.rpm
|
|
|
|
|