Debian releases new version of the 'mirror' package that fixes remote exploit
22 Oct. 1999
Summary
The version of mirror distributed in Debian GNU/Linux 2.1 could be remotely exploited. When mirroring a remote site the remote site could use filename-constructions like ".." that would cause mirror to work one level above the target directory for the mirrored files.
This has been fixed in mirror version 2.9-2.1.
Credit:
This information has been provided by: Wichert Akkerman.
Solution
Debian recommends that you upgrade your mirror package immediately. wget url
will fetch the file for you dpkg -i file.deb
will install the referenced file.
Debian GNU/Linux 2.1 alias slink
This version of Debian was released only for Intel, the Motorola 680x0, the alpha and the Sun sparc architecture.