Util-Linux Login Program Information Leakage Vulnerability

Solution:
Netwosix has released an advisory (NLSA-#2004-0010) to address this issue in Netwosix version 1.0 and 1.1. Please see the referenced advisory for more information. Fix is available below.

SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below.

Red Hat has made fixes for this issue available. See referenced advisory RHSA-2004:056-05 for additional details.

SGI has released an advisory 20040201-01-U with a patch to address this and other issues. Please see the referenced advisory for more information.

Fedora Legacy Update Advisory FLSA:1256 has been released to address this issue in Red Hat Linux.

SCO OpenLinux advisory CSSA-2004-016.0 and fixes have been released dealing with this issue.

Gentoo Linux has released GLSA 200404-06 advisory as well as fix information dealing with this issue. It has been recommended that the following action be taken to upgrade the vulnerable application:

All util-linux users should upgrade to version 2.12 or later:

# emerge sync

# emerge -pv ">=sys-apps/util-linux-2.12"
# emerge ">=sys-apps/util-linux-2.12"

Please see the referenced Gentoo advisory for more information.

Silicon Graphics has released advisory 20040406-01-U for Service Pack 2.4 dealing with this issue as well as others. Please see the referenced advisory for more information and details on obtaining fixes.


Netwosix Netwosix Linux 1.0

Netwosix Netwosix Linux 1.1

SGI ProPack 2.3

SGI ProPack 2.4

SCO OpenLinux Workstation 3.1.1

SCO OpenLinux Server 3.1.1


 

Privacy Statement
Copyright 2010, SecurityFocus