RM: pytris -- RoM; security issues; abandoned upstream
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
pytris (Debian) |
Fix Released
|
Unknown
|
|||
pytris (Ubuntu) |
Fix Released
|
High
|
Dustin Kirkland |
Bug Description
Imported from Debian bug 608689:
Package: pytris
Version: 0.98+nmu1
Severity: grave
Tags: security
Justification: user security hole
The setgid wrapper for this game makes no attempt at security.
It can trivially be used to execute code as group games, which can be
used to exploit other players of the game via the score file.
It could be fixed - the security team suggests dropping the shared score
file, and thus the wrapper. However, this package has not seen a
maintainer upload in years, and is stated as being unmaintained by the
author, on his website:
http://
I believe the best solution is removal, from unstable, squeeze, and
lenny.
Radovan, are you OK with reassigning this to ftp.debian.org?
SR
-- System Information:
Debian Release: squeeze/sid
APT prefers testing
APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_ZA.UTF-8, LC_CTYPE=
Shell: /bin/sh linked to /bin/dash
Versions of packages pytris depends on:
ii python 2.6.6-3+squeeze4 interactive high-level object-orie
pytris recommends no packages.
pytris suggests no packages.
-- no debconf information
security vulnerability: | no → yes |
Changed in pytris (Ubuntu): | |
importance: | Undecided → High |
status: | New → Confirmed |
Changed in pytris (Ubuntu): | |
status: | Confirmed → Fix Released |
Changed in pytris (Debian): | |
status: | Unknown → Fix Released |
Reviewed the documentation here, and removing, per request (showing Kate how to do so, in the process...)