Date: Fri, 17 Nov 2000 06:40:18 -0600 From: Bryan Paxton <bpaxton@SECURITYPORTAL.COM> Subject: LSLID:2000111702 - Kondara - man To: LINUX-SECURITY@LISTSERV.SECURITYPORTAL.COM LSLID:2000111702 man(2000/11/17) Description We are sorry this delayed response. The 'makewhatis' program included in the "man" package distributed in "Kondara MNU/Linux 1.2" has security hole which creates insecure files in /tmp. you should update the following software package. Thank you! RPMS/SRPMS alpha: ftp://ftp.st.ryukoku.ac.jp/pub/Linux/Kondara/Kondara-1.2/errata/alpha/man-1.5h1-12k.alpha.rpm i586: ftp://ftp.st.ryukoku.ac.jp/pub/Linux/Kondara/Kondara-1.2/errata/i586/man-1.5h1-12k.i586.rpm SRPMS: ftp://ftp.st.ryukoku.ac.jp/pub/Linux/Kondara/Kondara-1.2/errata/SRPMS/man-1.5h1-12k.nosrc.rpm References http://www.redhat.com/support/errata/RHSA-2000-041-02.html