Debians sikkerhedsbulletin
DSA-304-1 lv -- rettighedsforøgelse
- Rapporteret den:
- 15. maj 2003
- Berørte pakker:
- lv
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 7613.
I Mitres CVE-ordbog: CVE-2003-0188. - Yderligere oplysninger:
-
Leonard Stiles har opdaget, at lv, et flersproget program til visning af filer, indlæser indstillingerne fra en opsætningsfil i den aktuelle mappe. Fordi en sådan fil kunne være placeret der, af en ondsindet bruger og lv's opsætningsindstillinger kan anvendes til at udføre kommandoer, var dette et sikkerhedsproblem. En angriber kunne få rettighederne hørende til den bruger, der startede lv, deriblandt root.
I den stabile distribution (woody) er dette problem rettet i version 4.49.4-7woody2.
I den gamle stabile distribution (potato) er dette problem rettet i version 4.49.3-4potato2.
I den ustabile distribution (sid) er dette problem rettet i version 4.49.5-2.
Vi anbefaler at du opdaterer din lv-pakke.
- Rettet i:
-
Debian GNU/Linux 3.0 (woody)
- Kildekode:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2.dsc
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2.diff.gz
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4.orig.tar.gz
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.4-7woody2_sparc.deb
Debian GNU/Linux 2.2 (potato)
- Kildekode:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2.dsc
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2.diff.gz
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3.orig.tar.gz
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2_i386.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2_m68k.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2_powerpc.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/l/lv/lv_4.49.3-4potato2_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.
