Home > Security > Advisories

Advisories

Mandriva Advisories

Package name sgml-tools
Date March 15th, 2001
Advisory ID MDKSA-2001:030
Affected versions 6.0, 6.1, 7.1, 7.2, CS1.0
Synopsis Updated sgml-tools packages fix insecure handling of temporary files

Problem Description

Insecure handling of temporary file permissions can lead to other users
on a multi-user system being able to read the documents being
converted. This is due to sgml-tools creating temporary files without
any special permissions. The updated packages create a secure
temporary directory first, which is readable only by the owner, and
then create the temporary files in that secure directory.

Updated Packages

Mandrakelinux 6.0

 0dffdf59bf60b15f695a8f8cf1e0633e  6.0/RPMS/sgml-tools-1.0.9-3.1mdk.i586.rpm
67970748cf90806c3f11885245f38175  6.0/SRPMS/sgml-tools-1.0.9-3.1mdk.src.rpm

Mandrakelinux 6.1

 a9478714b0629d55de7aa2f48f0bfcb4  6.1/RPMS/sgml-tools-1.0.9-3.1mdk.i586.rpm
67970748cf90806c3f11885245f38175  6.1/SRPMS/sgml-tools-1.0.9-3.1mdk.src.rpm

Mandrakelinux 7.1

 40fb202d15e82d166efa06ea2108c87d  7.1/RPMS/sgml-tools-1.0.9-8.2mdk.i586.rpm
50720b8f4781c4542e0898f6d843b737  7.1/SRPMS/sgml-tools-1.0.9-8.2mdk.src.rpm

Mandrakelinux 7.2

 c5e48714e3da71f692e447eb942a368b  7.2/RPMS/sgml-tools-1.0.9-8.1mdk.i586.rpm
c2242855d3be03b899a908944c48ac1d  7.2/SRPMS/sgml-tools-1.0.9-8.1mdk.src.rpm

Corporate Server 1.0.1

 40fb202d15e82d166efa06ea2108c87d  1.0.1/RPMS/sgml-tools-1.0.9-8.2mdk.i586.rpm
50720b8f4781c4542e0898f6d843b737  1.0.1/SRPMS/sgml-tools-1.0.9-8.2mdk.src.rpm

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.