Yellow Dog Linux Security Announcement -------------------------------------- Package: diffutils Issue Date: December 08, 2001 Priority: low Advisory ID: YDU-20011208-6 1. Topic: Updated diffutils packages are now available, fixing a temporary file handling vulnerability in the sdiff program. 2. Problem: When using sdiff in interactive mode, a temporary file is created. The new diffutils packages make sure to create that file in a secure way. 3. Solution: a) Updating via yup... We suggest that you use the Yellow Dog Update Program (yup) to keep your system up-to-date. The following command(s) will automatically retrieve and install the fixed version of this update onto your system: yup update diffutils b) Updating manually... The update can also be retrieved manually from our ftp site below along with the rpm command that should be used to install the update. (Please use a mirror site) ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-2.1/ppc/ rpm -Fvh diffutils-2.7-23.ppc.rpm 4. Verification MD5 checksum Package -------------------------------- ---------------------------- 4e28a33fed9e8e0145eaf85a47efcd5a RPMS/diffutils-2.7-23.ppc.rpm ba9b1a7d02d1cac8f4ede36f9634cc8a SRPMS/diffutils-2.7-23.src.rpm If you wish to verify that each package has not been corrupted or tampered with, examine the md5sum with the following command: rpm --checksig --nogpg filename 5. Misc. Terra Soft has setup a moderated mailing list where these security, bugfix, and package enhancement announcements will be posted. See http://lists.yellowdoglinux.com/ for more information. For information regarding the usage of yup, the Yellow Dog Update Program, see http://http://www.yellowdoglinux.com/support/solutions/ydl_general/yup.shtml