[debian-goodies] [CVE-2007-3912] insufficient input sanitising

Bug #210128 reported by disabled.user
254
Affects Status Importance Assigned to Milestone
debian-goodies (Debian)
Fix Released
Unknown
debian-goodies (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: debian-goodies

References:
DSA-1527-1 (http://www.debian.org/security/2008/dsa-1527)

Quoting:
"Thomas de Grenier de Latour discovered that the checkrestart tool in the
debian-goodies suite of utilities, allowed local users to gain privileges
via shell metacharacters in the name of the executable file for a running
process."

CVE References

Revision history for this message
disabled.user (disabled.user-deactivatedaccount) wrote :

Argh, sorry, missed a cross-check... This has already been fixed in USN-526-1.

Changed in debian-goodies:
status: New → Fix Released
Changed in debian-goodies:
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.