Debian Security Advisory
DSA-1440-1 inotify-tools -- buffer overflow
- Date Reported:
- 28 Dec 2007
- Affected Packages:
- inotify-tools
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 443913.
In Mitre's CVE dictionary: CVE-2007-5037. - More information:
-
It was discovered that a buffer overflow in the filename processing of the inotify-tools, a command-line interface to inotify, may lead to the execution of arbitrary code. This only affects the internal library and none of the frontend tools shipped in Debian.
The old stable distribution (sarge) does not provide inotify-tools.
For the stable distribution (etch), this problem has been fixed in version 3.3-2.
For the unstable distribution (sid), this problem has been fixed in version 3.11-1.
We recommend that you upgrade your inotify-tools package.
- Fixed in:
-
Debian GNU/Linux 4.0 (stable)
- Source:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2.dsc
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3.orig.tar.gz
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2.diff.gz
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3.orig.tar.gz
- Alpha:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_arm.deb
- HP Precision:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_hppa.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_ia64.deb
- Big-endian MIPS:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_mips.deb
- Little-endian MIPS:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/i/inotify-tools/inotify-tools_3.3-2_sparc.deb
MD5 checksums of the listed files are available in the original advisory.