Secunia - Stay Secure
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Debian update for netpbm-free Advisory Available in Danish 

Secunia Advisory: SA10662  
Release Date: 2004-01-19

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid


CVE reference:CVE-2003-0924 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Debian has issued updated packages for netpbm-free. These fix an older vulnerability, allowing malicious users to escalate their privileges exploiting insecurely created temporary files.

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat.../netpbm-free/netpbm-free_9.20-8.4.dsc
Size/MD5 checksum: 662 2074eb1d13fa871111ec06f18ff57725
http://security.debian.org/pool/updat...pbm-free/netpbm-free_9.20-8.4.diff.gz
Size/MD5 checksum: 52834 0b7fbdc2e47c9a2a2e8da7eb54b98bb6
http://security.debian.org/pool/updat...pbm-free/netpbm-free_9.20.orig.tar.gz
Size/MD5 checksum: 1882851 0f153116c21bc7d2e167e574a486c22f

Alpha architecture:

http://security.debian.org/pool/updat...bm-free/libnetpbm9_9.20-8.4_alpha.deb
Size/MD5 checksum: 77762 1b6724adf13a90cf981122831e20165c
http://security.debian.org/pool/updat...ree/libnetpbm9-dev_9.20-8.4_alpha.deb
Size/MD5 checksum: 135466 ed7e2fb447336275d65c0e984553ac9e
http://security.debian.org/pool/updat...netpbm-free/netpbm_9.20-8.4_alpha.deb
Size/MD5 checksum: 1413784 feca605bc7f99fe0b7eb1fe5ae6e4e10

ARM architecture:

http://security.debian.org/pool/updat...tpbm-free/libnetpbm9_9.20-8.4_arm.deb
Size/MD5 checksum: 64148 b8151d91f4b6461d61aff5ca93186356
http://security.debian.org/pool/updat...-free/libnetpbm9-dev_9.20-8.4_arm.deb
Size/MD5 checksum: 125526 5ad7c026d001b8033f7249fb59574f5e
http://security.debian.org/pool/updat...n/netpbm-free/netpbm_9.20-8.4_arm.deb
Size/MD5 checksum: 1127644 e014fc4f87defe6d845288dc19a7f9dc

Intel IA-32 architecture:

http://security.debian.org/pool/updat...pbm-free/libnetpbm9_9.20-8.4_i386.deb
Size/MD5 checksum: 62450 6f7e06e132e08cabfd629d0cb89c7d98
http://security.debian.org/pool/updat...free/libnetpbm9-dev_9.20-8.4_i386.deb
Size/MD5 checksum: 103436 2c5d4e71e3de9bc55303d81a842c97f6
http://security.debian.org/pool/updat.../netpbm-free/netpbm_9.20-8.4_i386.deb
Size/MD5 checksum: 1079210 794d6f39a9f8cb427f1ca2569f1b10ec

Intel IA-64 architecture:

http://security.debian.org/pool/updat...pbm-free/libnetpbm9_9.20-8.4_ia64.deb
Size/MD5 checksum: 96534 8b8a73f914ec44486e23139547bc5c87
http://security.debian.org/pool/updat...free/libnetpbm9-dev_9.20-8.4_ia64.deb
Size/MD5 checksum: 170446 39927dc25960cb6db29a1ebe7d09436a
http://security.debian.org/pool/updat.../netpbm-free/netpbm_9.20-8.4_ia64.deb
Size/MD5 checksum: 1608638 6585784653a932078ba3354844e13fa7

HP Precision architecture:

http://security.debian.org/pool/updat...pbm-free/libnetpbm9_9.20-8.3_hppa.deb
Size/MD5 checksum: 83914 666e951ffedd72f5d2a4e6abe379f94d
http://security.debian.org/pool/updat...free/libnetpbm9-dev_9.20-8.3_hppa.deb
Size/MD5 checksum: 122954 bc35c5b3ca865b04c94b805ef3947b75
http://security.debian.org/pool/updat.../netpbm-free/netpbm_9.20-8.3_hppa.deb
Size/MD5 checksum: 1337394 248f5113d06737cb2d35c889fb26a95a

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...pbm-free/libnetpbm9_9.20-8.4_m68k.deb
Size/MD5 checksum: 62048 60f5dfaf168d9a8ed74194ffa3a4e299
http://security.debian.org/pool/updat...free/libnetpbm9-dev_9.20-8.4_m68k.deb
Size/MD5 checksum: 102256 909a64f8620188f4bb17fb84613f3f60
http://security.debian.org/pool/updat.../netpbm-free/netpbm_9.20-8.4_m68k.deb
Size/MD5 checksum: 1016512 5caf53f54597bf2944ed798a4fe6c299

Big endian MIPS architecture:

http://security.debian.org/pool/updat...pbm-free/libnetpbm9_9.20-8.4_mips.deb
Size/MD5 checksum: 66904 342b1aa43a2a9a5737d86d44a64a6025
http://security.debian.org/pool/updat...free/libnetpbm9-dev_9.20-8.4_mips.deb
Size/MD5 checksum: 123508 fbfa242ebee248d72f5f95874836fde4
http://security.debian.org/pool/updat.../netpbm-free/netpbm_9.20-8.4_mips.deb
Size/MD5 checksum: 1181146 4fdf19eedaf2e2dd070bd20524a68005

Little endian MIPS architecture:

http://security.debian.org/pool/updat...m-free/libnetpbm9_9.20-8.3_mipsel.deb
Size/MD5 checksum: 66740 b7552fba3606a3f58ebb452abf7f0fea
http://security.debian.org/pool/updat...ee/libnetpbm9-dev_9.20-8.3_mipsel.deb
Size/MD5 checksum: 123598 438cdf503b994fd3540f127ac1d31293
http://security.debian.org/pool/updat...etpbm-free/netpbm_9.20-8.3_mipsel.deb
Size/MD5 checksum: 1179992 e064c0325d910621134cc151c6f0b420

PowerPC architecture:

http://security.debian.org/pool/updat...-free/libnetpbm9_9.20-8.4_powerpc.deb
Size/MD5 checksum: 68940 aad85d5f1b3d9e959ceb11ce78d9a3b7
http://security.debian.org/pool/updat...e/libnetpbm9-dev_9.20-8.4_powerpc.deb
Size/MD5 checksum: 117868 f90c3780160363d358b072e458ec419e
http://security.debian.org/pool/updat...tpbm-free/netpbm_9.20-8.4_powerpc.deb
Size/MD5 checksum: 1153728 37e3b1719ed32004377410bfc49a82c5

IBM S/390 architecture:

http://security.debian.org/pool/updat...pbm-free/libnetpbm9_9.20-8.4_s390.deb
Size/MD5 checksum: 66696 6d600c371a05c4689b7f45d3800d70dc
http://security.debian.org/pool/updat...free/libnetpbm9-dev_9.20-8.4_s390.deb
Size/MD5 checksum: 116054 86fdf11619f0411cc4eac144d51556ce
http://security.debian.org/pool/updat.../netpbm-free/netpbm_9.20-8.4_s390.deb
Size/MD5 checksum: 1130276 b4d038d29e5c674d034bda4f989d976f

Sun Sparc architecture:

http://security.debian.org/pool/updat...bm-free/libnetpbm9_9.20-8.4_sparc.deb
Size/MD5 checksum: 65304 7a162f5688e187d6dd8f179a1a1bf7aa
http://security.debian.org/pool/updat...ree/libnetpbm9-dev_9.20-8.4_sparc.deb
Size/MD5 checksum: 118610 148bb94f30313a348ba2c7570734d4e3
http://security.debian.org/pool/updat...netpbm-free/netpbm_9.20-8.4_sparc.deb
Size/MD5 checksum: 1435468 69ab0007d50cf12a59de32d29e5e5f8b


-- Debian GNU/Linux unstable alias sid --

Fixed in version 2:9.25-9.

Original Advisory:
http://www.debian.org/security/2004/dsa-426



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

1277 Related Secunia Security Advisories, displaying 10

1. Debian update for tiff
2. Debian update for libxml2
3. Debian update for postfix
4. Debian update for pdns
5. Debian update for httracker
6. Debian update for opensc
7. Debian update for cupsys
8. Debian update for libxslt
9. Debian update for newsx
10. Debian update for ruby1.9

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
OpenOffice "rtl_allocateMe mory()" Truncation Vulnerability
2.
HP-UX update for Apache
3.
Red Hat Directory Server Multiple Vulnerabilities
4.
Red Hat Directory Server Denial of Service Vulnerabilities
5.
Tiger "genmsgidx" Insecure Temporary Files
6.
JustSystems Ichitaro Products Unspecified Code Execution Vulnerability
7.
Red Hat update for tomcat
8.
R "javareconf" Insecure Temporary Files
9.
Citadel "migrate_aliase s.sh" Insecure Temporary Files
10.
Mono Sys.Web HTTP Header Injection Vulnerability





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia