Yellow Dog Linux Security Announcement -------------------------------------- Package: docbook-utils Issue Date: May 02, 2002 Priority: medium Advisory ID: YDU-20020502-7 1. Topic: Updated docbook-utils packages are available. 2. Problem: "DocBook is a document markup language that can be transformed into other formats using a stylesheet. The default stylesheet provided with [Yellow Dog] Linux has an insecure option enabled. The default stylesheet used when converting a DocBook document to multiple HTML files allows an untrusted document to write files outside of the current directory. This is because element identifiers (specified in the document) are used to form the names of the output files. If an untrusted document uses a full pathname as an identifier, it can cause that file to be written to -- as long as the user performing the conversion has write access. Updated docbook-utils packages are available that disable this feature and enable filenames to be generated based on the type of the element rather than its identifier. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0169 to this issue." (from the Red Hat Advisory) 3. Solution: a) Updating via yup... We suggest that you use the Yellow Dog Update Program (yup) to keep your system up-to-date. The following command(s) will automatically retrieve and install the fixed version of this update onto your system: yup update docbook-utils b) Updating manually... The update can also be retrieved manually from our ftp site below along with the rpm command that should be used to install the update. (Please use a mirror site) ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-2.2/ppc/ rpm -Fvh docbook-utils-*0.6.9-25.noarch.rpm 4. Verification MD5 checksum Package -------------------------------- ---------------------------- c6640f77bd37f9a57573d2cac907cb45 ppc/docbook-utils-0.6.9-25.noarch.rpm 21cefbc5a74eedec36f99b2fc8b706ba ppc/docbook-utils-pdf-0.6.9-25.noarch.rpm 53387163a53e663259603a617b1cd0c9 SRPMS/docbook-utils-0.6.9-25.src.rpm If you wish to verify that each package has not been corrupted or tampered with, examine the md5sum with the following command: rpm --checksig --nogpg filename 5. Misc. Terra Soft has setup a moderated mailing list where these security, bugfix, and package enhancement announcements will be posted. See http://lists.yellowdoglinux.com/ for more information. For information regarding the usage of yup, the Yellow Dog Update Program, see http://http://www.yellowdoglinux.com/support/solutions/ydl_general/yup.shtml