Changelog for
cdrtools-devel-2.01a14-1.i386.rpm :
Sat May 17 14:00:00 2003 PLD Team
All persons listed below can be reached at AATTpld.org.pl
$Log: cdrtools.spec,v $
Revision 1.66.2.1 2003/05/13 18:34:53 misi3k
- security update to 2.01a14
BUG(bugtraq):
From: Stefano Di Paola
X-Sender: jhackAATTJohnWayne.iol.it
To: bugtraqAATTsecurityfocus.com
Subject: cdrtools2.0 Format String Vulnerability
SUMMARY : Format String
SEVERITY : local root exploit if suid (on several distros)
i would inform you that there is a format string vulnerability
in cdrecord 2.0 and in particular in libscg/scsiopen.c in line 273
Revision 1.66 2003/05/01 16:30:35 misiek
- fix compilation on 2.5
Revision 1.65 2003/04/30 16:59:00 aflinta
- version 2.01a12
Revision 1.64 2003/04/23 20:26:09 areq
- 2.01a11
Revision 1.63 2003/04/17 00:08:13 kloczek
- added man patch with: s#/var/adm/messages#/var/log/messages#;
s#/uasr/local#/usr# fixes in man pages,
- cut %changelog.