yast2-perl-bindings: YaST2 - Perl Bindings ---------------------------------------------------------------------- File: yast2-perl-bindings-2.9.34-1.5.i586.rpm Patchrpm: yast2-perl-bindings-2.9.34-1.5.i586.patch.rpm Version: 2.9.34-1.5 Size: 113 kB Patchsize: 103 kB Date: Sat 15 Oct 2005 16:13:55 CEST Source: yast2-perl-bindings-2.9.34-1.5.src.rpm Security: Yes ---------------------------------------------------------------------- Description: Rene "l00m" Fischer found two problem in the handling of package repositories. - The remote repositories were copied with permissions and ownerships intact. If the remote repository was owned by a user or had problematic permissions, these ownership and permissions were copied over to the system. If these included world writeable permissions local users could overwrite package meta files. This problem is not present when installing from CD or a correctly set up network source. - The YaST package handling had a bufferoverflow which could be used by attackers having access to the meta data (for instance due to above permission problem) to potentially execute code. (CAN-2005-3013) These problems have been fixed with this update.