USN-165-1: heartbeat vulnerability
11 August 2005
heartbeat vulnerability
Releases
Details
Eric Romang discovered that heartbeat created temporary files in an
insecure manner. This could allow a symlink attack to create or
overwrite arbitrary files with root privileges as soon as heartbeat is
started.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.04
-
heartbeat
-
Ubuntu 4.10
-
heartbeat
-
In general, a standard system update will make all the necessary changes.