Debian Security Advisory

DLA-876-1 eject -- LTS security update

Date Reported:
28 Mar 2017
Affected Packages:
eject
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-6964.
More information:

Ilja Van Sprundel discovered that eject (a tool to eject CD/DVD drives) did not properly handle errors returned from setuid/setgid.

For Debian 7 Wheezy, this issue has been fixed in eject version 2.1.5+deb1+cvs20081104-13+deb7u1.

We recommend that you upgrade your eject packages.