Bug 117310 - Vulnerability fix for CAN-2003-0853 not applied
Summary: Vulnerability fix for CAN-2003-0853 not applied
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: coreutils
Version: 1
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Tim Waugh
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-03-02 19:15 UTC by Philip K. Warren
Modified: 2007-11-30 22:10 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-03-12 16:12:11 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Philip K. Warren 2004-03-02 19:15:21 UTC
Description of problem:
The vulnerability described in CAN-2003-0853
(http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0853) and
fixed in Redhat 9 (http://rhn.redhat.com/errata/RHSA-2003-309.html)
and Redhat Enterprise
(http://rhn.redhat.com/errata/RHSA-2003-310.html) does not seem to be
applied to the version of coreutils found in Fedora Core 1.

Version-Release number of selected component (if applicable):
coreutils-5.0-24

Comment 1 Tim Waugh 2004-03-03 10:43:19 UTC
Eek!  Looks like you're right.

Comment 2 Tim Waugh 2004-03-03 15:54:37 UTC
Note that wu-ftpd is not shipped in Fedora Core 1, and vsftpd uses an
ls built-in.


Note You need to log in before you can comment on or make changes to this bug.