In some instances, if dump is suid root, it can be used to gain root
access. Two exploits have been published to prove this.
Linux-Mandrake ships dump suid root, however both exploits do not work
under Linux-Mandrake. The end result is a shell that is suid by the
user attempting the exploit, and not suid root which is the intended
To upgrade automatically, use MandrivaUpdate.
Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :
rpm --checksig package.rpm
You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.
If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.