Trustix developers discovered insecure temporary file creation in
supplemental scripts in the gzip package that can allows local users
to overwrite files via a symlink attack.
Please let me know which version fixes these problems in sid/sarge
while I take care of the package in woody.
I'm attaching the patch from Trustix and the patch I'm using for the
package in woody.
Regards,
Joey
--
This is GNU/Linux Country. On a quiet night, you can hear Windows reboot.
Please always Cc to me when replying to me on the lists.
Package: gzip
Version: 1.3.5-9
Severity: grave
Tags: sarge, sid, security, patch
Trustix developers discovered insecure temporary file creation in
supplemental scripts in the gzip package that can allows local users
to overwrite files via a symlink attack.
Please let me know which version fixes these problems in sid/sarge
while I take care of the package in woody.
I'm attaching the patch from Trustix and the patch I'm using for the
package in woody.
Regards,
Joey
--
This is GNU/Linux Country. On a quiet night, you can hear Windows reboot.
Please always Cc to me when replying to me on the lists.