-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2003-17
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Original released date : 19 Mar 2003
Last revised : 19 Mar 2003
Package : kernel
Summry : The ptrace is in vulnerability
More information :
The kernel 2.2 and 2.4 have a flaw in ptrace.
Impact :
The local users may be able to gain root privileges.
Affected Products :
- Turbolinux 8 Server
- Turbolinux 8 Workstation
- Turbolinux 7 Server
- Turbolinux 7 Workstation
- Turbolinux Server 6.5
- Turbolinux Advanced Server 6
- Turbolinux Server 6.1
- Turbolinux Workstation 6.0
Solution :
Please use turbopkg tool to apply the update.
<Turbolinux 8 Server>
Source Packages
Size : MD5
kernel-2.4.18-10.src.rpm
41266288 11fdd65206b71693efc06a16cecfcf5f
Binary Packages
Size : MD5
kernel-2.4.18-10.i586.rpm
13920638 207ff0151250c445b1607c80c5e7a720
kernel-BOOT-2.4.18-10.i586.rpm
6965920 83fd4a706f8e8e1a2a67561026add1f4
kernel-doc-2.4.18-10.i586.rpm
1460384 bb9cfe02701d1bea16b2b5bc8f07673a
kernel-headers-2.4.18-10.i586.rpm
1817936 d1b3f7e5cad294982de782f0b14fe52e
kernel-pcmcia-cs-2.4.18-10.i586.rpm
326504 c7435624222492615ee6770a990885af
kernel-smp-2.4.18-10.i586.rpm
14441843 1a06e863f4d0bb5f8e330b179699b0e8
kernel-smp64G-2.4.18-10.i586.rpm
14412380 a28200006ed1d948c16f15c913f25303
kernel-source-2.4.18-10.i586.rpm
26339117 46bd8ac64444b263c7e32be9dcbcf22c
<Turbolinux 8 Workstation>
Source Packages
Size : MD5
kernel-2.4.18-10.src.rpm
41266288 11fdd65206b71693efc06a16cecfcf5f
Binary Packages
Size : MD5
kernel-2.4.18-10.i586.rpm
13920638 207ff0151250c445b1607c80c5e7a720
kernel-BOOT-2.4.18-10.i586.rpm
6965920 83fd4a706f8e8e1a2a67561026add1f4
kernel-doc-2.4.18-10.i586.rpm
1460384 bb9cfe02701d1bea16b2b5bc8f07673a
kernel-headers-2.4.18-10.i586.rpm
1817936 d1b3f7e5cad294982de782f0b14fe52e
kernel-pcmcia-cs-2.4.18-10.i586.rpm
326504 c7435624222492615ee6770a990885af
kernel-smp-2.4.18-10.i586.rpm
14441843 1a06e863f4d0bb5f8e330b179699b0e8
kernel-smp64G-2.4.18-10.i586.rpm
14412380 a28200006ed1d948c16f15c913f25303
kernel-source-2.4.18-10.i586.rpm
26339117 46bd8ac64444b263c7e32be9dcbcf22c
<Turbolinux 7 Server>
Source Packages
Size : MD5
kernel-2.4.18-10.src.rpm
41266288 11fdd65206b71693efc06a16cecfcf5f
Binary Packages
Size : MD5
kernel-2.4.18-10.i586.rpm
13920638 207ff0151250c445b1607c80c5e7a720
kernel-BOOT-2.4.18-10.i586.rpm
6965920 83fd4a706f8e8e1a2a67561026add1f4
kernel-doc-2.4.18-10.i586.rpm
1460384 bb9cfe02701d1bea16b2b5bc8f07673a
kernel-headers-2.4.18-10.i586.rpm
1817936 d1b3f7e5cad294982de782f0b14fe52e
kernel-pcmcia-cs-2.4.18-10.i586.rpm
326504 c7435624222492615ee6770a990885af
kernel-smp-2.4.18-10.i586.rpm
14441843 1a06e863f4d0bb5f8e330b179699b0e8
kernel-smp64G-2.4.18-10.i586.rpm
14412380 a28200006ed1d948c16f15c913f25303
kernel-source-2.4.18-10.i586.rpm
26339117 46bd8ac64444b263c7e32be9dcbcf22c
<Turbolinux 7 Workstation>
Source Packages
Size : MD5
kernel-2.4.18-10.src.rpm
41266288 11fdd65206b71693efc06a16cecfcf5f
Binary Packages
Size : MD5
kernel-2.4.18-10.i586.rpm
13920638 207ff0151250c445b1607c80c5e7a720
kernel-BOOT-2.4.18-10.i586.rpm
6965920 83fd4a706f8e8e1a2a67561026add1f4
kernel-doc-2.4.18-10.i586.rpm
1460384 bb9cfe02701d1bea16b2b5bc8f07673a
kernel-headers-2.4.18-10.i586.rpm
1817936 d1b3f7e5cad294982de782f0b14fe52e
kernel-pcmcia-cs-2.4.18-10.i586.rpm
326504 c7435624222492615ee6770a990885af
kernel-smp-2.4.18-10.i586.rpm
14441843 1a06e863f4d0bb5f8e330b179699b0e8
kernel-smp64G-2.4.18-10.i586.rpm
14412380 a28200006ed1d948c16f15c913f25303
kernel-source-2.4.18-10.i586.rpm
26339117 46bd8ac64444b263c7e32be9dcbcf22c
<Turbolinux Server 6.5>
Source Packages
Size : MD5
kernel-2.2.18-18.src.rpm
26504292 7fc133e78fb81572dd1375bbdf34e51b
Binary Packages
Size : MD5
kernel-2.2.18-18.i386.rpm
9774982 1f5e6dd96cd772e13b2f3d3f2fb6b59b
kernel-BOOT-2.2.18-18.i386.rpm
7891146 245aad1b0bad2631653f076bbee903cb
kernel-doc-2.2.18-18.i386.rpm
1079038 04dfedddf4503c67533e16bc9089663c
kernel-headers-2.2.18-18.i386.rpm
1313496 f8c0d25a94a97ff33cbd5f01726359ad
kernel-ibcs-2.2.18-18.i386.rpm
50600 62c65d10938b36825c66a4e69f3e01d0
kernel-pcmcia-cs-2.2.18-18.i386.rpm
347991 047374c1c963d86ec154ca6921a427e5
kernel-smp-2.2.18-18.i386.rpm
10060263 513704433ec4865891d98dbdb77db867
kernel-source-2.2.18-18.i386.rpm
22816316 5568344b051aab25c62b9826d22dbf9a
kernel-utils-2.2.18-18.i386.rpm
169803 020537e3675b77a8f0f2350b8772b0c6
<Turbolinux Advanced Server 6>
Source Packages
Size : MD5
kernel-2.2.18-18.src.rpm
26504292 1aa27f6d2916214c736cabdf7e380e76
Binary Packages
Size : MD5
kernel-2.2.18-18.i386.rpm
9774982 1f5e6dd96cd772e13b2f3d3f2fb6b59b
kernel-BOOT-2.2.18-18.i386.rpm
7891146 e1b7d253b09a2149f0929c5b1694efbf
kernel-doc-2.2.18-18.i386.rpm
1079038 77b68cc2ce6be9dd3ec9969b0f4dd43b
kernel-headers-2.2.18-18.i386.rpm
1313496 f45c70923b0a1b7c10b82f4306b238b9
kernel-ibcs-2.2.18-18.i386.rpm
50600 7bf19b0c990d3e0d0cbdde505458342e
kernel-pcmcia-cs-2.2.18-18.i386.rpm
347991 5a58d3587936f23f5b70c6078eeb314a
kernel-smp-2.2.18-18.i386.rpm
10060263 7d6410bddc5963e6afc9c406d2efb46f
kernel-source-2.2.18-18.i386.rpm
22816316 0608d9edfaa09a9bb8cc7f085a4f7ddf
kernel-utils-2.2.18-18.i386.rpm
169803 04923e809a7ebb0ce58a57a9584db4ef
<Turbolinux Server 6.1>
Source Packages
Size : MD5
kernel-2.2.18-18.src.rpm
26504292 cf5a2e47f98449a4202393d8c54a51cd
Binary Packages
Size : MD5
kernel-2.2.18-18.i386.rpm
9774982 1f5e6dd96cd772e13b2f3d3f2fb6b59b
kernel-BOOT-2.2.18-18.i386.rpm
7891146 1e91565a1dde5d5bd1852ad8c51b373e
kernel-doc-2.2.18-18.i386.rpm
1079038 6fb23cdd48cdc7a72ec41229425500ed
kernel-headers-2.2.18-18.i386.rpm
1313496 38045358ee95e20637e4486690cc90cf
kernel-ibcs-2.2.18-18.i386.rpm
50600 9b5afdc9a3b24380d6d8e289acc25158
kernel-pcmcia-cs-2.2.18-18.i386.rpm
347991 3a2cf6a96a1548dcaf7b1534bcf363f2
kernel-smp-2.2.18-18.i386.rpm
10060263 c7d4e4703c676d86a5d10d5d6f10cdcb
kernel-source-2.2.18-18.i386.rpm
22816316 b5cb00b80874d9a668030d2777821006
kernel-utils-2.2.18-18.i386.rpm
169803 634446942d305da92df148bfcbc0808a
<Turbolinux Workstation 6.0>
Source Packages
Size : MD5
kernel-2.2.18-18.src.rpm
26504292 5eb5b42da40ebf88367a4a7dda3c7b39
Binary Packages
Size : MD5
kernel-2.2.18-18.i386.rpm
9774982 1f5e6dd96cd772e13b2f3d3f2fb6b59b
kernel-BOOT-2.2.18-18.i386.rpm
7891146 b091cf0f4a09db860e678dc67430e53e
kernel-doc-2.2.18-18.i386.rpm
1079038 8a07a5bbc13bab47e2228abf317e1478
kernel-headers-2.2.18-18.i386.rpm
1313496 40f205522395fdf48f6dcfe3ad0966d2
kernel-ibcs-2.2.18-18.i386.rpm
50600 6818b048353dc391c187cc00c8f25331
kernel-pcmcia-cs-2.2.18-18.i386.rpm
347991 b9c528d7e09a2d44df1cbb1d2109b5cc
kernel-smp-2.2.18-18.i386.rpm
10060263 071f770646d836f1e21dfc2b992cbaf8
kernel-source-2.2.18-18.i386.rpm
22816316 84abc0cd1284191ca69357d0ff351134
kernel-utils-2.2.18-18.i386.rpm
169803 252bf22a09870f1e7e3163dbd97ac56c
References :
CVE
[
CAN-2003-0127]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0127
--------------------------------------------------------------------------
Revision History
19 Mar 2003 Initial release
--------------------------------------------------------------------------
Copyright(C) 2003 Turbolinux, Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQE+d8L4K0LzjOqIJMwRAoAiAKCtpwemgKKj3/INaPueGVUyCCqr7QCfcVFn
UnV2tmOZ6bHkcxExeOfvt5g=
=oaHa
-----END PGP SIGNATURE-----