int(1199)

Vulnerability Bulletins


Múltiples vulnerabilidades en emulador atari800 de Linux

Vulnerability classification

Property Value
Confidence level Oficial
Impact Compromiso Root
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software atari800 <= 1.3

Description

Se han encontrado múltiples vulnerabilidades en el emulador de Atari atari800, que permitirían a un usuario local obtener privilegios de root.

La gravedad de la vulnerabilidad se debe a que uno de los programas afectados se instala por defecto con setuid root para poder acceder directamente al hardware de vídeo.

Solution



Actualización de software

Debian Linux

Debian Linux 3.0
Source:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3.dsc
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3.diff.gz
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_alpha.deb
ARM:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_ia64.deb
HPPA:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/contrib/a/atari800/atari800_1.2.2-1woody3_sparc.deb

Standar resources

Property Value
CVE CAN-2004-1076
BID 11756

Other resources

Debian Security Advisory DSA-609-1
http://www.debian.org/security/2004/dsa-609

Version history

Version Comments Date
1.0 Aviso emitido 2004-12-15
Ministerio de Defensa
CNI
CCN
CCN-CERT