SciLinux: CVE-2007-0235 libgtop2 SL4.x i386/x86_64
Summary
Date: Wed, 8 Aug 2007 14:58:00 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for libgtop2 on SL4.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Moderate: libgtop2 security updateIssue date: 2007-08-07CVE Names: CVE-2007-0235A flaw was found in the way libgtop2 handled long filenames mappedinto the address space of a process. An attacker could execute arbitrarycode on behalf of the user running gnome-system-monitor by executing aprocess and mapping a file with a specially crafted name into theprocesses' address space. (CVE-2007-0235)This update also fixes the following bug:* when a version of libgtop2 compiled to run on a 32-bit architecture wasused to inspect a process running in 64-bit mode, it failed to reportcertain information regarding address space mapping correctly.SL 4.x SRPMS: libgtop2-2.8.0-1.0.2.src.rpm i386: libgtop2-2.8.0-1.0.2.i386.rpm libgtop2-devel-2.8.0-1.0.2.i386.rpm x86_64: libgtop2-2.8.0-1.0.2.i386.rpm libgtop2-2.8.0-1.0.2.x86_64.rpm libgtop2-devel-2.8.0-1.0.2.x86_64.rpm-Connie Sieh-Troy Dawson