what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 33895

Secunia Security Advisory 33895
Posted Feb 18, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for fglrx-installer. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

tags | advisory, local
systems | linux, ubuntu
SHA-256 | 308d216a297bb0041e844ba21f0b662dc242e0734cdbb7e0324626ca972d10c3

Secunia Security Advisory 33895

Change Mirror Download
----------------------------------------------------------------------

Did you know that a change in our assessment rating, exploit code
availability, or if an updated patch is released by the vendor, is
not part of this mailing-list?

Click here to learn more:
https://secunia.com/advisories/business_solutions/

----------------------------------------------------------------------

TITLE:
Ubuntu update for fglrx-installer

SECUNIA ADVISORY ID:
SA33895

VERIFY ADVISORY:
https://secunia.com/advisories/33895/

DESCRIPTION:
Ubuntu has issued an update for fglrx-installer. This fixes a
vulnerability, which can be exploited by malicious, local users to
perform certain actions with escalated privileges.

The vulnerability is caused due to the installer creating an insecure
LD_LIBRARY_PATH on 64bit systems. This can be exploited to execute
arbitrary code with privileges of the user running the affected
binaries by causing the binaries to load a malicious shared library
from the current directory.

SOLUTION:
Apply updated packages.

-- Ubuntu 8.10 --

Source archives:

https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-installer_8.543-0ubuntu4.1.diff.gz
Size/MD5: 26000 8fd05a4ab9e9f04c59ed5b731bcacd8b
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-installer_8.543-0ubuntu4.1.dsc
Size/MD5: 1443 e7dee56d6c645ff3bce0c3093af205e3
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-installer_8.543.orig.tar.gz
Size/MD5: 47046692 6abc8e86f1a00168ba8f43d58f71cb69

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

https://security.ubuntu.com/ubuntu/pool/main/f/fglrx-installer/fglrx-modaliases_8.543-0ubuntu4.1_amd64.deb
Size/MD5: 10938 8f0014e73c06b1fd0e586359067641c7
https://security.ubuntu.com/ubuntu/pool/multiverse/f/fglrx-installer/libamdxvba1_8.543-0ubuntu4.1_amd64.deb
Size/MD5: 846038 8982e97324d57a3db0072123d2406a56
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-amdcccle_8.543-0ubuntu4.1_amd64.deb
Size/MD5: 6630112 72d48d2e40f3bb63b7ad9b66367d5dca
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-kernel-source_8.543-0ubuntu4.1_amd64.deb
Size/MD5: 1430276 cd88c1a040f050472b82406308e28ec5
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/xorg-driver-fglrx-dev_8.543-0ubuntu4.1_amd64.deb
Size/MD5: 83402 8b2fc26c7f1e2417613e543428d5b21f
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/xorg-driver-fglrx_8.543-0ubuntu4.1_amd64.deb
Size/MD5: 17264298 e26cff93ff7eb4cddede61ea41b81aee

i386 architecture (x86 compatible Intel/AMD):

https://security.ubuntu.com/ubuntu/pool/main/f/fglrx-installer/fglrx-modaliases_8.543-0ubuntu4.1_i386.deb
Size/MD5: 10938 2fc0c5d1a8c799df60ee474b10e57e0a
https://security.ubuntu.com/ubuntu/pool/multiverse/f/fglrx-installer/libamdxvba1_8.543-0ubuntu4.1_i386.deb
Size/MD5: 412474 c23a19c9e238b0cc8986b98910c0da9d
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-amdcccle_8.543-0ubuntu4.1_i386.deb
Size/MD5: 6749062 80263acaf045f9a196d8a2486dc42969
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/fglrx-kernel-source_8.543-0ubuntu4.1_i386.deb
Size/MD5: 1368946 18257688f659b91d95746e1b509edc5d
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/xorg-driver-fglrx-dev_8.543-0ubuntu4.1_i386.deb
Size/MD5: 78658 537cc59d4b86274114f0eeb5febdf283
https://security.ubuntu.com/ubuntu/pool/restricted/f/fglrx-installer/xorg-driver-fglrx_8.543-0ubuntu4.1_i386.deb
Size/MD5: 11915472 d392662d6ecefae8992c12c0356b63fa

PROVIDED AND/OR DISCOVERED BY:
Marko Lindqvist

ORIGINAL ADVISORY:
USN-721-1:
https://lists.ubuntu.com/archives/ubuntu-security-announce/2009-February/000841.html

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
https://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
https://secunia.com/advisories/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close