Debian Security Advisory

DSA-076-1 most -- buffer overflow

Date Reported:
18 Sep 2001
Affected Packages:
Security database references:
In the Bugtraq database (at SecurityFocus): BugTraq ID 3347.
In Mitre's CVE dictionary: CVE-2001-0961.
More information:
Pavel Machek has found a buffer overflow in the `most' pager program. The problem is part of most's tab expansion where the program would write beyond the bounds two array variables when viewing a malicious file. This could lead into other data structures being overwritten which in turn could enable most to execute arbitrary code being able to compromise the users environment.

This has been fixed in the upstream version 4.9.2 and an updated version of 4.9.0 for Debian GNU/Linux 2.2.

We recommend that you upgrade your most package immediately.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Intel ia32:
Motorola 680x0:
Sun Sparc:

MD5 checksums of the listed files are available in the original advisory.