Home > Security > Advisories

Advisories

Mandriva Advisories

Package name dump
Date November 2nd, 2000
Advisory ID MDKSA-2000:065
Affected versions 6.0, 6.1, 7.0, 7.1, 7.2
Synopsis Linux-Mandrake is not vulnerable to insecure environment variables with dump

Problem Description

In some instances, if dump is suid root, it can be used to gain root
access. Two exploits have been published to prove this.

Linux-Mandrake ships dump suid root, however both exploits do not work
under Linux-Mandrake. The end result is a shell that is suid by the
user attempting the exploit, and not suid root which is the intended
result.

Updated Packages


Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.