Secunia Logo
Netsikker nu! 2008
 
Ubuntu update for cfengine
Secunia Advisory: SA17142
Release Date: 2005-10-11
Popularity: 6,181 views

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Ubuntu Linux 4.10
Ubuntu Linux 5.04

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2005-2960
CVE-2005-3137


Description:
Ubuntu has issued an update for cfengine. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges.

For more information:
SA17037

Solution:
Apply updated packages.

-- Ubuntu 4.10 (Warty Warthog) --

Source archives:

http://security.ubuntu.com/ubuntu/poo...fengine_1.6.5-1ubuntu0.4.10.1.diff.gz
Size/MD5: 102867 ebd2d4596fe81bad3f87b69c0a1057cd
http://security.ubuntu.com/ubuntu/poo...ne/cfengine_1.6.5-1ubuntu0.4.10.1.dsc
Size/MD5: 704 1cde3ab958c48f9cb64eb7005e44bfe9
http://security.ubuntu.com/ubuntu/poo.../cfengine_1.6.5-1ubuntu0.4.10.diff.gz
Size/MD5: 102863 0fe4462348ac5db6e48f5ae4200223ee
http://security.ubuntu.com/ubuntu/poo...c/cfengine/cfengine_1.6.5.orig.tar.gz
Size/MD5: 880066 fc02d8d56433f32020c3030192cad66e

Architecture independent packages:

http://security.ubuntu.com/ubuntu/poo...ine-doc_1.6.5-1ubuntu0.4.10.1_all.deb
Size/MD5: 351924 ed29a178c45c8c539ef3b04afcefded0

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...ngine_1.6.5-1ubuntu0.4.10.1_amd64.deb
Size/MD5: 353892 44c62122d59a5f0974ad033dc6e80b4a

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...engine_1.6.5-1ubuntu0.4.10.1_i386.deb
Size/MD5: 311784 cb66ad235cfdbe07a8f29d9d09f5e073

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...ine_1.6.5-1ubuntu0.4.10.1_powerpc.deb
Size/MD5: 354564 4bdd42ce5b05c00bc314cb06df597dc3

-- Ubuntu 5.04 (Hoary Hedgehog) --

Source archives:

http://security.ubuntu.com/ubuntu/poo...fengine_1.6.5-1ubuntu0.5.04.1.diff.gz
Size/MD5: 102866 335e8d60109f38507a1f869a58595564
http://security.ubuntu.com/ubuntu/poo...ne/cfengine_1.6.5-1ubuntu0.5.04.1.dsc
Size/MD5: 704 a942df3e7d86a6d1f86126ddb648e6e9
http://security.ubuntu.com/ubuntu/poo...c/cfengine/cfengine_1.6.5.orig.tar.gz
Size/MD5: 880066 fc02d8d56433f32020c3030192cad66e

Architecture independent packages:

http://security.ubuntu.com/ubuntu/poo...ine-doc_1.6.5-1ubuntu0.5.04.1_all.deb
Size/MD5: 386022 fcac1e988bae93f33c5da1ea37014055

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...ngine_1.6.5-1ubuntu0.5.04.1_amd64.deb
Size/MD5: 353878 073ffd567f5b5bfaa3160e878b46d9ba

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...engine_1.6.5-1ubuntu0.5.04.1_i386.deb
Size/MD5: 311104 23232672fe6e8eb10f25133cf59680a9

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...ine_1.6.5-1ubuntu0.5.04.1_powerpc.deb
Size/MD5: 354586 107e028030519395ee526224bdf31da5

Original Advisory:
http://www.ubuntu.com/usn/usn-198-1

Other References:
SA17037:
http://secunia.com/advisories/17037/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 9
New vulnerabilities: 29
Updated advisories: 10

Highly // 122 views
SUSE update for MozillaFirefox
Moderately // 137 views
Debian update for lighttpd

6th Oct, 2008
New advisories: 19
New vulnerabilities: 52
Updated advisories: 26


Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. SUSE update for MozillaFirefox // 113 views
2. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 109 views
3. HP-UX NFS/ONCplus Denial of Service Vulnerability // 86 views
4. IBM Lotus Quickr Security Issues and Denial of Service // 85 views
5. D-Bus "_dbus_validate_signature_with_reason()" Denial of Service // 75 views
6. iseemedia LPViewer ActiveX Control Multiple Buffer Overflow Vulnerabilities // 71 views
7. Kwalbum "UploaditemsPage.php" File Upload Vulnerability // 67 views
8. Debian update for lighttpd // 61 views
9. Microsoft Windows Vista Page Fault Handling Denial of Service // 50 views
10. Serv-U File Renaming Directory Traversal and STOU Denial of Service // 36 views