-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2003-19
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Original released date : 25 Mar 2003
Last revised : 25 Mar 2003
Package : rxvt
Summry : A number of vulnerabilities in the handling of escape sequences
More information :
The problem which cannot process the escape sequences correctly exists in rxvt.
Impact :
When a specific character code which included escape sequences is displayed by the rxvt,
the third party may be able to execute arbitrary shell command.
Affected Products :
- Turbolinux 8 Server
- Turbolinux 8 Workstation
- Turbolinux 7 Server
- Turbolinux 7 Workstation
- Turbolinux Server 6.5
- Turbolinux Advanced Server 6
- Turbolinux Server 6.1
- Turbolinux Workstation 6.0
Solution :
Please use turbopkg tool to apply the update.
Please also refer to the References for further information.
<Turbolinux 8 Server>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 7838af94232ee37cef7380db38c7c726
Binary Packages
Size : MD5
rxvt-2.7.6-16.i586.rpm
199537 3dd1d61ed61f67f08862e37a09bff5b6
<Turbolinux 8 Workstation>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 ac44eb42db4c209b38fdb4f00665a883
Binary Packages
Size : MD5
rxvt-2.7.6-16.i586.rpm
199446 5cf575194a173d1e01733f31c8e65ecd
<Turbolinux 7 Server>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 2b99b261247d3644c7dcbe6074d8a2e2
Binary Packages
Size : MD5
rxvt-2.7.6-16.i586.rpm
195384 d5f0f6fe367e48c260358d5d265fa52d
<Turbolinux 7 Workstation>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 ecbeae108e8f2b7828e1bf2d9ed2724b
Binary Packages
Size : MD5
rxvt-2.7.6-16.i586.rpm
195366 17ec7dcd5fbd30e4c093ca911325d8f3
<Turbolinux Server 6.5>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 fce92d08efcbcf02737705928dc69b60
Binary Packages
Size : MD5
rxvt-2.7.6-16.i386.rpm
213412 bee3cd5c12a79414ebbaa424137b4950
<Turbolinux Advanced Server 6>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 9b366125bb83b553553cefc90f62e87a
Binary Packages
Size : MD5
rxvt-2.7.6-16.i386.rpm
213396 2f9f9639ec89b91d469f1bd584e800c8
<Turbolinux Server 6.1>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 c55f5e289ce1198e38d1b8add47eff4f
Binary Packages
Size : MD5
rxvt-2.7.6-16.i386.rpm
211105 253bf88a77a27bbe54f84311e59851bf
<Turbolinux Workstation 6.0>
Source Packages
Size : MD5
rxvt-2.7.6-16.src.rpm
498739 3e01ca6c2147285f8ab576d0b41f91a6
Binary Packages
Size : MD5
rxvt-2.7.6-16.i386.rpm
213416 921e84c9e96925be5bad92d51bc771fa
References :
CVE
[
CAN-2003-00022]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0022
[
CAN-2003-00023]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0023
[
CAN-2003-00066]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0066
--------------------------------------------------------------------------
Revision History
25 Mar 2003 Initial release
--------------------------------------------------------------------------
Copyright(C) 2003 Turbolinux, Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQE+f7luK0LzjOqIJMwRArAzAJ41v4fIRGyvKylYPx1fKJ6fRA1ZYQCgle87
UeReZgTMgCvetQUOuyKhcZs=
=w3Lc
-----END PGP SIGNATURE-----