Debian Security Advisory
DSA-3823-1 eject -- security update
- Date Reported:
- 28 Mar 2017
- Affected Packages:
- eject
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 858872.
In Mitre's CVE dictionary: CVE-2017-6964. - More information:
-
Ilja Van Sprundel discovered that the dmcrypt-get-device helper used to check if a given device is an encrypted device handled by devmapper, and used in eject, does not check return values from setuid() and setgid() when dropping privileges.
For the stable distribution (jessie), this problem has been fixed in version 2.1.5+deb1+cvs20081104-13.1+deb8u1.
For the unstable distribution (sid), this problem has been fixed in version 2.1.5+deb1+cvs20081104-13.2.
We recommend that you upgrade your eject packages.