-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -------------------------------------------------------------------------- PACKAGE : screen SUMMARY : Fix for screen vulnerability DATE : 2004-01-20 08:53:00 ID : CLA-2004:809 RELEVANT RELEASES : 8, 9 - ------------------------------------------------------------------------- DESCRIPTION Screen[1] is a program which allows the use of several sessions inside a single terminal. Timo Sirainen reported[2] a buffer overflow vulnerability[3] in the screen package which could be exploited by an attacker who is able to send about 2Gb of data to the user's screen session. Additionally, a fix for a potential problem with window sizes has been incorporated in these updated packages. Please note that screen is not installed setuid/setgid. SOLUTION It is recommended that all screen users upgrade their packages. REFERENCES 1. http://www.gnu.org/software/screen/ 2. http://marc.theaimsgroup.com/?l=bugtraq&m=106995837813873&w=2 3. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0972 UPDATED PACKAGES ftp://atualizacoes.conectiva.com.br/8/SRPMS/screen-3.9.10-2U80_1cl.src.rpm ftp://atualizacoes.conectiva.com.br/8/RPMS/screen-3.9.10-2U80_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/SRPMS/screen-3.9.13-24126U90_1cl.src.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/screen-3.9.13-24126U90_1cl.i386.rpm ADDITIONAL INSTRUCTIONS The apt tool can be used to perform RPM packages upgrades: - run: apt-get update - after that, execute: apt-get upgrade Detailed instructions reagarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en - ------------------------------------------------------------------------- All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en - ------------------------------------------------------------------------- All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en - ------------------------------------------------------------------------- Copyright (c) 2004 Conectiva Inc. http://www.conectiva.com - ------------------------------------------------------------------------- subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFADQi142jd0JmAcZARAkUPAKCBlgb3eJMPGUJd2jVNnym5yGR6PwCZAWQm O9oKN+dLAyr3JbRv9nWjY/0= =6Dq8 -----END PGP SIGNATURE-----