-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2003-35
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Original released date : 06 Jun 2003
Last revised : 06 Jun 2003
Package : lv
Summary : Privilege escalation
More information :
lv is a powerful multilingual file viewer.
~/.lv configuration file may allow local users to execute arbitrary
commands as other lv users by placing malicious .lv files into other
directories.
Impact :
An attackers may be able to gain the privileges of the user invoking lv.
Affected Products :
- Turbolinux 8 Server
- Turbolinux 8 Workstation
- Turbolinux 7 Server
- Turbolinux 7 Workstation
Solution :
Please use turbopkg tool to apply the update.
<Turbolinux 8 Server>
Source Packages
Size : MD5
lv-4.49.5-1.src.rpm
582373 60e910da41bf36d500e4d54129c7d507
Binary Packages
Size : MD5
lv-4.49.5-1.i586.rpm
426952 3415fd360da405e5cb9c10c6573ee1ef
<Turbolinux 8 Workstation>
Source Packages
Size : MD5
lv-4.49.5-1.src.rpm
582373 38d8b7c70ded794a65ed0809d16c3427
Binary Packages
Size : MD5
lv-4.49.5-1.i586.rpm
426925 5851212c264ae909ad05399b3e8e9231
<Turbolinux 7 Server>
Source Packages
Size : MD5
lv-4.49.5-1.src.rpm
582373 fd2c9a9d23daeb9b593564462cf5e771
Binary Packages
Size : MD5
lv-4.49.5-1.i586.rpm
424793 5f3579ff33f339e73e43b093d5de8e8a
<Turbolinux 7 Workstation>
Source Packages
Size : MD5
lv-4.49.5-1.src.rpm
582373 853cdf5b5eb6205538422bf8f39c4039
Binary Packages
Size : MD5
lv-4.49.5-1.i586.rpm
424923 0b814534203aeb16ac16fe801c46041e
References :
LV Release Note
http://www.ff.iij4u.or.jp/~nrt/lv/relnote.html
CVE
[
CAN-2003-0188]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0188
--------------------------------------------------------------------------
Revision History
06 Jun 2003 Initial release
--------------------------------------------------------------------------
Copyright(C) 2003 Turbolinux, Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
iD8DBQE+4CA0K0LzjOqIJMwRArYkAKC0T1YD0D3QVHeIfQyYb80vKmcjtQCfZ+DZ
LjATFjlo/4M1b0Jme0vymC0=
=AOsP
-----END PGP SIGNATURE-----