Navigation
|
|
| Problem Description |
A problem with how kdm manages the ~/.dmrc file was discovered by
Ludwig Nussel. By using a symlink attack, a local user could get kdm
to read arbitrary files on the system, including privileged system
files and those belonging to other users.
Mandriva's mdkkdm also suffers from this same problem and has been
patched to correct it. Only Corporate 3 is affected; in Mandriva Linux
2006, mdkkdm is in contribs.
| Updated Packages |
Corporate Server 3.0
dd234f9831a30157879e25b29a14cf2f corporate/3.0/RPMS/mdkkdm-9.2-22.1.C30mdk.i586.rpm 043b4a58f3a101482a21afe8ca5d162b corporate/3.0/SRPMS/mdkkdm-9.2-22.1.C30mdk.src.rpm
Corporate Server 3.0/X86_64
d1350d31ceb08dc68b1184469d23fea5 x86_64/corporate/3.0/RPMS/mdkkdm-9.2-22.1.C30mdk.x86_64.rpm 043b4a58f3a101482a21afe8ca5d162b x86_64/corporate/3.0/SRPMS/mdkkdm-9.2-22.1.C30mdk.src.rpm
| References |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2449
| Upgrade |
To upgrade automatically, use MandrivaUpdate.
| Verification |
Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :
rpm --checksig package.rpm
You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.
If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.
