- Issued:
- 2003-02-07
- Updated:
- 2003-05-22
RHSA-2003:038 - Security Advisory
Synopsis
im security update
Type/Severity
Security Advisory: Low
Topic
Updated Internet Message packages are available that fix the insecure
handling of temporary files.
[Updated 9 April 2003]
Added packages for Red Hat Linux Advanced Workstation, Red Hat Enterprise
Linux ES, and Red Hat Enterprise Linux WS.
Description
Internet Message (IM) consists of a set of user interface commands and
backend Perl5 libraries to integrate email and the NetNews user interface.
These commands are designed to be used from both the Mew mail reader for
Emacs and the command line.
A vulnerability has been discovered by Tatsuya Kinoshita in the way two IM
utilities create temporary files. By anticipating the names used to
create files and directories stored in the /tmp directory, it may be
possible for a local attacker to corrupt or modify data as another user.
Users of IM are advised to install these packages which contain a
backported patch to correct these issues.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Affected Products
- Red Hat Enterprise Linux Server 2 ia64
- Red Hat Enterprise Linux Server 2 i386
- Red Hat Enterprise Linux Workstation 2 ia64
- Red Hat Enterprise Linux Workstation 2 i386
Fixes
- BZ - 79079 - security vulnerability in "Internet Message"
CVEs
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.