Date: Mon, 7 Dec 1998 21:24:42 +0100
From: Wichert Akkerman <wichert@cs.leidenuniv.nl>
To: Debian Security Announce <debian-security-announce@lists.debian.org>
Subject: [SECURITY] New version of fte fixes access problems
--+HP7ph2BbKc20aGI
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
We have found that the fte package as supplied in our slink (frozen)
and potato (unstable) archives does not drop its root priviliges
after initializing the virtual console device. This allows all users
to read and write files with root priviliges, and execute all programs
as root.
A new package (version 0.46b-4.1) has been uploaded to fix this problem.=20
We recommend that you upgrade your fte package immediately.
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
Debian GNU/Linux 2.0 alias hamm
-------------------------------
The fte package in this release does not suffer from this problem.
Debian GNU/Linux 2.1 alias slink (not released yet)
---------------------------------------------------
Source archives:
ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-=
4.1.diff.gz
MD5 checksum: 44c60f6b5b55c80f7634eb405f3707e5
ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-=
4.1.dsc
MD5 checksum: e8991ea4fe2e298b57432e80dc5fd0b8
ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5.=
orig.tar.gz
MD5 checksum: 255f2f8cd2c210b497fdcdb0b9f964ed
Intel architecture:
ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte-co=
nsole_0.46b5-4.1.deb
MD5 checksum: 0d3d146749f68b11f6aed19d64161bbe
ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte_0.=
46b5-4.1.deb
MD5 checksum: 39a33e02915d6cc594b9170d0fc9b0f8
Motorola 680x0 architecture:
ftp://ftp.debian.org/debian/dists/slink/main/binary-m68k/editors/fte-co=
nsole_0.46b5-4.1_m68k.deb
MD5 checksum: 117675708c4b3b1afbdbac5e63c997b0
ftp://ftp.debian.org/debian/dists/slink/main/binary-m68k/editors/fte_0.=
46b5-4.1_m68k.deb
MD5 checksum: 9c7fb9a6f7b89025afb8cfa63a4da0ec
For not yet released architectures please refer to the appropriate
directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .
--=20
Debian GNU/Linux . Security Managers . security@debian.org
debian-security-announce@lists.debian.org
Christian Hudon . Wichert Akkerman . Martin Schulze
<chrish@debian.org> . <wakkerma@debian.org> . <joey@debian.org>
--+HP7ph2BbKc20aGI
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
iQB1AwUBNmw5iqjZR/ntlUftAQF+ywL+No+QnXvS9+1o5IZ3mUkHa9DqHxvXNHL1
R8bA/6MeLwPf0szw1ZTaKRQypWa/EjmcoA8mrjhib6Fqqr8RCPYIQgeiWXxzlQib
0eAOfmAXY5sFx7mCsmuaq8oDQ0q8H/X6
=o/q0
-----END PGP SIGNATURE-----
--+HP7ph2BbKc20aGI--
--
To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org