Comment 0 for bug 9811

Revision history for this message
In , Martin Schulze (joey-infodrom) wrote :

Package: gzip
Version: 1.3.5-9
Severity: grave
Tags: sarge, sid, security, patch

Trustix developers discovered insecure temporary file creation in
supplemental scripts in the gzip package that can allows local users
to overwrite files via a symlink attack.

Please let me know which version fixes these problems in sid/sarge
while I take care of the package in woody.

I'm attaching the patch from Trustix and the patch I'm using for the
package in woody.

Regards,

 Joey

--
This is GNU/Linux Country. On a quiet night, you can hear Windows reboot.

Please always Cc to me when replying to me on the lists.