Bugtraq mailing list archives

[Debian] Re: fte-console has root compromise bug]


From: aleph1 () UNDERGROUND ORG (Aleph One)
Date: Mon, 7 Dec 1998 11:22:19 -0800


--fUYQa+Pmc3FrFX/N
Content-Type: text/plain; charset=us-ascii


--
Aleph One / aleph1 () underground org
http://underground.org/
KeyID 1024/948FD6B5
Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01

--fUYQa+Pmc3FrFX/N
Content-Type: message/rfc822
Content-Description: Forwarded message from Wichert Akkerman <wakkerma () cs leidenuniv nl>

Received: (qmail 10937 invoked from network); 7 Dec 1998 02:09:16 -0000
Received: from murphy.debian.org (HELO murphy.novare.net) (209.176.56.6)
  by underground.org with SMTP; 7 Dec 1998 02:09:16 -0000
Received: (qmail 5439 invoked by uid 38); 7 Dec 1998 00:55:32 -0000
Resent-Date: 7 Dec 1998 00:55:32 -0000
Resent-Cc: recipient list not shown: ;
X-Envelope-Sender: wichert () cs leidenuniv nl
Message-ID: <19981207020214.B4372 () cs leidenuniv nl>
Date: Mon, 7 Dec 1998 02:02:14 +0100
From: Wichert Akkerman <wakkerma () cs leidenuniv nl>
To: Ben Collins <bmc () visi net>,
  Debian Security Announce <debian-security-announce () lists debian org>
Subject: Re: fte-console has root compromise bug
References: <19981205200346.B32334 () visi net>
Mime-Version: 1.0
Content-Type: multipart/signed; protocol="application/pgp-signature";
        micalg=pgp-md5; boundary=9dgjiU4MmWPVapMU
In-Reply-To: <19981205200346.B32334 () visi net>; from Ben Collins on Sat, Dec 05, 1998 at 08:03:47PM -0500
X-Debian: PGP check passed for security officers
Priority: urgent
Reply-To: security () debian org
Resent-Message-ID: <"JkYkX.A.zUB.Deya2"@murphy>
Resent-From: debian-security-announce () lists debian org
X-Mailing-List: <debian-security-announce () lists debian org> archive/latest/35
X-Loop: debian-security-announce () lists debian org
Precedence: list
Resent-Sender: debian-security-announce-request () lists debian org


--9dgjiU4MmWPVapMU
Content-Type: multipart/mixed; boundary=da4uJneut+ArUgXk


--da4uJneut+ArUgXk
Content-Type: text/plain; charset=us-ascii


I just wrote this advisory. I'm currently waiting for the m68k porters
to recompile it before releasing it.

Wichert.

--
==============================================================================
This combination of bytes forms a message written to you by Wichert Akkerman.
E-Mail: wakkerma () cs leidenuniv nl
WWW: http://www.wi.leidenuniv.nl/~wichert/

--da4uJneut+ArUgXk
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment; filename=fte

Subject: [SECURITY] New versions of fte fixes access problems

We have found that the fte package as supplied in our slink (frozen
and potato (unstable) archives does not drop its root priviliges
after initializing the virtual console device. This allows all users
to read and write files with root priviliges, and execute all programs
as root.

A new package (version 0.46b-4.1) has been uploaded to fix this problem.

We recommend that you upgrade your fte package immediately.

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

Debian GNU/Linux 2.0 alias hamm
-------------------------------

  fte was not released for this (or earlier) release.


Debian GNU/Linux 2.1 alias slink (not released yet)
---------------------------------------------------

  Source archives:
    ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-4.1.diff.gz
      MD5 checksum: 44c60f6b5b55c80f7634eb405f3707e5
    ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-4.1.dsc
      MD5 checksum: e8991ea4fe2e298b57432e80dc5fd0b8
    ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5.orig.tar.gz
      MD5 checksum: 255f2f8cd2c210b497fdcdb0b9f964ed

  Intel architecture:
    ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte-console_0.46b5-4.1.deb
      MD5 checksum: 0d3d146749f68b11f6aed19d64161bbe
    ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte_0.46b5-4.1.deb
      MD5 checksum: 39a33e02915d6cc594b9170d0fc9b0f8

For not yet released architectures please refer to the appropriate
directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .

--
Debian GNU/Linux      .   Security Managers      .   security () debian org
              debian-security-announce () lists debian org
  Christian Hudon     .     Wichert Akkerman     .     Martin Schulze
<chrish () debian org>   .   <wakkerma () debian org>  .   <joey () debian org>

--da4uJneut+ArUgXk--

--9dgjiU4MmWPVapMU
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia

iQB1AwUBNmspFqjZR/ntlUftAQEF5gL9FFZaMy6PaVrnVtd+UZclrVE2t8lG9tCo
I6UDORb989Yei76uLC8LjKiXPCgAYs/uYk5WU+g6L08iLy3RliIxgCblBj0ZIWI4
iXzErwUiCjGGFVXXrR6CklnDxujkrtPo
=4Whn
-----END PGP SIGNATURE-----

--9dgjiU4MmWPVapMU--


--
To UNSUBSCRIBE, email to debian-security-announce-request () lists debian org
with a subject of "unsubscribe". Trouble? Contact listmaster () lists debian org


--fUYQa+Pmc3FrFX/N--



Current thread: