[Full-disclosure] rPSA-2006-0219-1 info install-info texinfo
rPath Update Announcements
announce-noreply at rpath.com
Mon Nov 27 15:44:06 GMT 2006
rPath Security Advisory: 2006-0219-1
Published: 2006-11-27
Products: rPath Linux 1
Rating: Minor
Exposure Level Classification:
Indirect User Deterministic Unauthorized Access
Updated Versions:
info=/conary.rpath.com at rpl:devel//1/4.8-6.2-1
install-info=/conary.rpath.com at rpl:devel//1/4.8-6.2-1
texinfo=/conary.rpath.com at rpl:devel//1/4.8-6.2-1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4810
https://issues.rpath.com/browse/RPL-810
Description:
Previous versions of the texinfo package can be caused to execute
arbitrary code contained in an intentionally malformed texinfo
file. These texinfo commands are often run automatically when
building software packages.
Full-Disclosure is hosted and sponsored by Secunia.