SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for cdrtools-devel-2.01a14-1.i586.rpm :
Sat May 17 14:00:00 2003 PLD Team
All persons listed below can be reached at AATTpld.org.pl

$Log: cdrtools.spec,v $
Revision 1.66.2.1 2003/05/13 18:34:53 misi3k
- security update to 2.01a14

BUG(bugtraq):
From: Stefano Di Paola
X-Sender: jhackAATTJohnWayne.iol.it
To: bugtraqAATTsecurityfocus.com
Subject: cdrtools2.0 Format String Vulnerability

SUMMARY : Format String
SEVERITY : local root exploit if suid (on several distros)

i would inform you that there is a format string vulnerability
in cdrecord 2.0 and in particular in libscg/scsiopen.c in line 273

Revision 1.66 2003/05/01 16:30:35 misiek
- fix compilation on 2.5

Revision 1.65 2003/04/30 16:59:00 aflinta
- version 2.01a12

Revision 1.64 2003/04/23 20:26:09 areq
- 2.01a11

Revision 1.63 2003/04/17 00:08:13 kloczek
- added man patch with: s#/var/adm/messages#/var/log/messages#;
s#/uasr/local#/usr# fixes in man pages,
- cut %changelog.


 
ICM