Debians sikkerhedsbulletin

DSA-2011-1 dpkg -- stigennemløb

Rapporteret den:
10. mar 2010
Berørte pakker:
dpkg
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Mitres CVE-ordbog: CVE-2010-0396.
Yderligere oplysninger:

William Grant opdagede at dpkg-source-komponenten i dpkg, lavniveauinfrastrukturen til håndtering af installering og fjernelse af Debian-softwarepakker, var sårbar over for stigennemløbsangreb. En særligt fremstillet Debian-kildekodepakke, kunne føre til filændringer uden for målmappen, når pakkens indhold blev pakket ud.

I den stabile distribution (lenny), er dette problem rettet i version 1.14.29.

I distributionen testing (squeeze) og i den ustabile distribution (sid) vil disse problemer snart blive rettet.

Vi anbefaler at du opgraderer dine dpkg-pakker.

Rettet i:

Debian GNU/Linux 5.0 (lenny)

Kildekode:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29.dsc
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29.tar.gz
Arkitekturuafhængig komponent:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg-dev_1.14.29_all.deb
Alpha:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_alpha.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_amd64.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_arm.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_arm.deb
ARM EABI:
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_armel.deb
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_armel.deb
HP Precision:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_hppa.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_i386.deb
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_ia64.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_ia64.deb
Big-endian MIPS:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_mips.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_mips.deb
Little-endian MIPS:
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_mipsel.deb
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_powerpc.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_s390.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29_sparc.deb
http://security.debian.org/pool/updates/main/d/dpkg/dselect_1.14.29_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.