6439784 2001-05-02 11:24 +0200 /22 rader/ Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE> Sänt av: joel@lysator.liu.se Importerad: 2001-05-02 18:20 av Brevbäraren Extern mottagare: BUGTRAQ@SECURITYFOCUS.COM Externa svar till: Florian.Weimer@RUS.UNI-STUTTGART.DE Mottagare: Bugtraq (import) <16873> Kommentar till text 6402418 av <debian-security-announce@LISTS.DEBIAN.ORG> Ärende: Re: [SECURITY] [DSA 052-1] New sendfile packages fix root exploit ------------------------------------------------------------ From: Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE> To: BUGTRAQ@SECURITYFOCUS.COM Message-ID: <tgk840gl3i.fsf@mercury.rus.uni-stuttgart.de> debian-security-announce@LISTS.DEBIAN.ORG writes: > Package : sendfile > Vulnerability : broken privileges dropping > Problem-Type : local root exploit > Debian-specific: no The author, Ulli Horlacher, released an updated version of sendfile which corrects these problems a few months ago. It's available from: ftp://ftp.belwue.de/pub/unix/sendfile/ -- Florian Weimer Florian.Weimer@RUS.Uni-Stuttgart.DE University of Stuttgart http://cert.uni-stuttgart.de/ RUS-CERT +49-711-685-5973/fax +49-711-685-5898 (6439784) /Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE>/