|
|
| |
| Topi Miettinen audited elvis-tiny and raised an issue covering the use and creation of temporary files. Those files are created with a predictable pattern and O_EXCL flag is not used when opening. This makes users of elvis-tiny vulnerable to race conditions and/or data corruption. |
| |
Credit:
The information has been provided by Debian security announce.
|
| |
Vulnerable systems:
Debian GNU/Linux 2.1 alias slink
Solution:
This problem has been fixed in version 1.4-10 and it is recommended that you upgrade your elvis-tiny packages immediately.
This problem does not exist in the big elvis package.
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
Debian GNU/Linux 2.1 alias slink
Slink is no longer being supported by the Debian Security Team. It is highly recommended you upgrade to the current stable release.
Debian GNU/Linux 2.2 alias potato
Potato was released for the Alpha, ARM, Intel ia32, Motorola 680x0, PowerPC and Sun SPARC architectures. Fixes are available for all of them and will be included in 2.2r2.
Source archives:
http://security.debian.org/dists/potato/updates/main/source/elvis-tiny_1.4-10.diff.gz
http://security.debian.org/dists/potato/updates/main/source/elvis-tiny_1.4-10.dsc
http://security.debian.org/dists/potato/updates/main/source/elvis-tiny_1.4.orig.tar.gz
Alpha architecture:
http://security.debian.org/dists/potato/updates/main/binary-alpha/elvis-tiny_1.4-10_alpha.deb
ARM architecture:
http://security.debian.org/dists/potato/updates/main/binary-arm/elvis-tiny_1.4-10_arm.deb
Intel ia32 architecture:
http://security.debian.org/dists/potato/updates/main/binary-i386/elvis-tiny_1.4-10_i386.deb
Motorola 680x0 architecture:
http://security.debian.org/dists/potato/updates/main/binary-m68k/elvis-tiny_1.4-10_m68k.deb
PowerPC architecture:
http://security.debian.org/dists/potato/updates/main/binary-powerpc/elvis-tiny_1.4-10_powerpc.deb
Sun Sparc architecture:
http://security.debian.org/dists/potato/updates/main/binary-sparc/elvis-tiny_1.4-10_sparc.deb
|
|
|