|
Family: Debian Local Security Checks --> Category: infos
[DSA730] DSA-730-1 bzip2 Vulnerability Scan
Vulnerability Scan Summary DSA-730-1 bzip2
Detailed Explanation for this Vulnerability Test
Imran Ghory discovered a race condition in bzip2, a high-quality
block-sorting file compressor and decompressor. When decompressing a
file in a directory a possible hacker has access to, bunzip2 could be
tricked to set the file permissions to a different file the user has
permissions to.
For the stable distribution (woody) this problem has been fixed in
version 1.0.2-1.woody2.
For the testing distribution (sarge) this problem has been fixed in
version 1.0.2-6.
For the unstable distribution (sid) this problem has been fixed in
version 1.0.2-6.
We recommend that you upgrade your bzip2 packages.
Solution : http://www.debian.org/security/2005/dsa-730
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|