Debians sikkerhedsbulletin

DSA-472-1 fte -- flere sårbarheder

Rapporteret den:
3. apr 2004
Berørte pakker:
fte
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Debians fejlsporingssystem: Fejl 203871.
I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 10041.
I Mitres CVE-ordbog: CVE-2003-0648.
CERTs noter om sårbarheder, bulletiner og hændelser: VU#900964, VU#354838.
Yderligere oplysninger:

Steve Kemp og Jaguar har opdaget flere bufferoverløbssårbarheder i vfte, en udgave af fte-editoren som kører under Linux-konsollen, i pakken fte-console. Dette program er setuid root for at udvøre visse systemnære handlinger fra konsollen.

På grund af disse fejl, er setuid-rettigheden fjernet fra vfte, hvilket gør at det kun er brugbart af root. Vi anbefaler i stedet at anvende terminaludgaven (i fte-terminal-pakken), som kører på alle kapable terminaler, deriblandt også Linux-konsollen.

I den stabile distribution (woody) er disse problemer rettet i version 0.49.13-15woody1.

I den ustabile distribution (sid) er disse problemer rettet i version 0.50.0-1.1.

Vi anbefaler at du opdaterer din fte-pakke.

Rettet i:

Debian GNU/Linux 3.0 (woody)

Kildekode:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1.dsc
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_alpha.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_alpha.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_alpha.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_alpha.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_arm.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_arm.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_arm.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_arm.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_i386.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_i386.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_i386.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_i386.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_ia64.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_ia64.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_ia64.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_ia64.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_hppa.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_hppa.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_hppa.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_hppa.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_m68k.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_m68k.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_m68k.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_m68k.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_mips.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_mips.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_mips.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_mips.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_mipsel.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_mipsel.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_mipsel.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_mipsel.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_powerpc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_powerpc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_powerpc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_powerpc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_s390.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_s390.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_s390.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_s390.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/f/fte/fte_0.49.13-15woody1_sparc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-console_0.49.13-15woody1_sparc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-docs_0.49.13-15woody1_sparc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-terminal_0.49.13-15woody1_sparc.deb
http://security.debian.org/pool/updates/main/f/fte/fte-xwindow_0.49.13-15woody1_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.