[PLDSA 30-1] New mrtg packages fix wrong persion

Krzysiek Taraszka dzimi at pld.org.pl
Sat May 3 14:45:59 CEST 2003


- --------------------------------------------------------------------------
PLD Security Advisory PLDSA 30-1                        security at pld.org.pl
http://www.pld.org.pl/security/                          PLD Security Team
14 February 2003 			http://www.pld.org.pl/security/faq
- --------------------------------------------------------------------------

Package        : prior to mrtg-2.9.22-1
Vulnerability  : wrong permision
Problem-Type   : local
PLD-specific   : yes

The Multi Router Traffic Grapher (MRTG) is a tool to monitor the traffic 
load on network-links. PLD packages have got wrong permision to /etc/mrtg 
directory witch allow others to get snmp passwords.
Permisions to /etc/mrtg directory should be - root only.

The above problems have been fixed in version 2.9.25-2 for the
current stable distribution (ra).

We recommend that you upgrade your mrtg packages.

wget -c url
	will fetch the file for you
rpm -Uhv file(s)*.rpm
        will upgrade the referenced file.

If you are using "poldek" - the package manager, use the line as given below
for upgrade packages

poldek --update
        will update the internal database
poldek --upgrade 'mrtg*'
        will install corrected packages

If you are using "apt" - the package manager, use the line as given below
for upgrade packages

apt-get update
        will update the internal database
apt-get upgrade 'mrtg*'
        will install corrected packages

PLD Linux 1.0 alias ra
- --------------------

  Source archives:

ftp://ftp.pld.org.pl/dists/ra/updates/security/SRPMS/mrtg-2.9.25-2.src.rpm
       MD5 checksum: 52bd41a06ebae0185f6d15da77176316

  I386 Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/i386/mrtg-2.9.25-2.i386.rpm
       MD5 checksum: 0581335b0744275ccb002f3e80d66c21


  I586 Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/i586/mrtg-2.9.25-2.i586.rpm
       MD5 checksum: d496e4de1e749e37a5e49c60c4021671


  I686 Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/i686/mrtg-2.9.25-2.i686.rpm
       MD5 checksum: 379930c010c052cd5bdf16474f10c3b8


  PowerPC Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/ppc/mrtg-2.9.25-2.ppc.rpm
       MD5 checksum: d5fbf1d3f301d97ccc4e58ac8844332c


-
--------------------------------------------------------------------------------
-
If you are using poldek add this line to poldek.conf.
If you are using apt-get add this line to sources.list.

For i386 architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/i386/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/i386 base updates-security
For i586 architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/i586/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/i586 base updates-security
For i686 architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/i686/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/i686 base updates-security
For ppc architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/ppc/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/ppc base updates-security



More information about the pld-security-announce mailing list