Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Netpbm Temporary File Vulnerabilities

Solution:
SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below.

Red Hat has released an advisory (RHSA-2004:031-02) and fixes to address this issue in Enterprise products. Customers who are subscribed to the Red Hat Network may obtain fixes by running the up2date utility. Further information can be found in the referenced advisory.

Debian has issued fixes. See advisory DSA-426-1 in the reference section.

RedHat has released an advisory RHSA-2004:030-01 with updated NetPBM packages to address this issue. Please see the referenced advisory for more information.

SGI has released an advisory 20040201-01-U with a patch to address this and other issues. Please see the referenced advisory for more information.

Mandrake has released advisory MDKSA-2004:011 with fixes to address this issue.

Mandrake has released advisory MDKSA-2004:011-1 along with updated fixes dealing with this issue. Apparently the previous patches failed to properly implement a call to 'mktemp' causing some failures. Reportedly there are no security issues around this update; it is simply a bug fix. Please see the referenced advisory for more information.

Gentoo Linux has released an advisory (GLSA 200410-02) along with an updated dealing with this issue. Gentoo advises that all Netpbm users should upgrade to an unaffected version:

# emerge sync

# emerge -pv ">=media-libs/netpbm-10.0"
# emerge ">=media-libs/netpbm-10.0"

For more information please see the referenced Gentoo Linux advisory for more information.

Conectiva has released advisory CLA-2004:909 to address these issues. Please see the referenced advisory for more information.

Turbolinux has released advisory 20050207 [TURBOLINUX SECURITY INFO] 07/Feb/2005 to address various issues. Please see the referenced advisory for more information.


RedHat netpbm-devel-9.24-10.i386.rpm

RedHat netpbm-9.24-10.i386.rpm

RedHat netpbm-progs-9.24-10.i386.rpm

SGI ProPack 2.3

SGI ProPack 2.4

Netpbm Netpbm 9.14

Netpbm Netpbm 9.20

Netpbm Netpbm 9.24

Netpbm Netpbm 9.25







 

Privacy Statement
Copyright 2008, SecurityFocus