Privacy and Legal Notice

CIRC INFORMATION BULLETIN

Q-033: Libgda2

[Debian Security Advisory DSA-871-1]

October 25, 2005 17:00 GMT

PROBLEM: Two format string vulnerabilities in libgda2, the GNOME Data Access library for GNOME2.
PLATFORM: Debian GNU/Linux 3.1 alias sarge
DAMAGE: May lead to the execution of arbitrary code in programs that use this library.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is LOW. A user may execute arbitrary code by taking advantaage of the format string vulnerabilities through an executable code that is built upon the library libgda2.

LINKS:  
  CIRC BULLETIN: http://www.doecirc.energy.gov/bulletins/q-033.shtml
  ORIGINAL BULLETIN: http://www.debian.org/security/2005/dsa-871
  CVE: CVE-2005-2958

[***** Start Debian Security Advisory DSA-871-1 *****]


Debian Security Advisory

DSA-871-1 libgda2 -- format string

Date Reported:
25 Oct 2005
Affected Packages:
libgda2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CAN-2005-2958.
More information:

Steve Kemp discovered two format string vulnerabilities in libgda2, the GNOME Data Access library for GNOME2, which may lead to the execution of arbitrary code in programs that use this library.

The old stable distribution (woody) is not affected by these problems.

For the stable distribution (sarge) these problems have been fixed in version 1.2.1-2sarge1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your libgda2 packages.

Fixed in:

Debian GNU/Linux 3.1 (sarge)

Source:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2.dsc
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2.diff.gz
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.8p7-1.2_sparc.deb

MD5 checksums of the listed files are available in the original advisory.




[***** End Debian Security Advisory DSA-871-1 *****]

   

CIRC wishes to acknowledge the contributions of Debian for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/