[Debian] Re: fte-console has root compromise bug]

From: Aleph One (aleph1at_private)
Date: Mon Dec 07 1998 - 11:22:19 PST

  • Next message: Mark Spencer: "Cheops"

    --fUYQa+Pmc3FrFX/N
    Content-Type: text/plain; charset=us-ascii
    
    
    --
    Aleph One / aleph1at_private
    http://underground.org/
    KeyID 1024/948FD6B5
    Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01
    
    --fUYQa+Pmc3FrFX/N
    Content-Type: message/rfc822
    Content-Description: Forwarded message from Wichert Akkerman <wakkermaat_private>
    
    Received: (qmail 10937 invoked from network); 7 Dec 1998 02:09:16 -0000
    Received: from murphy.debian.org (HELO murphy.novare.net) (209.176.56.6)
      by underground.org with SMTP; 7 Dec 1998 02:09:16 -0000
    Received: (qmail 5439 invoked by uid 38); 7 Dec 1998 00:55:32 -0000
    Resent-Date: 7 Dec 1998 00:55:32 -0000
    Resent-Cc: recipient list not shown: ;
    X-Envelope-Sender: wichertat_private
    Message-ID: <19981207020214.B4372at_private>
    Date: Mon, 7 Dec 1998 02:02:14 +0100
    From: Wichert Akkerman <wakkermaat_private>
    To: Ben Collins <bmcat_private>,
      Debian Security Announce <debian-security-announceat_private>
    Subject: Re: fte-console has root compromise bug
    References: <19981205200346.B32334at_private>
    Mime-Version: 1.0
    Content-Type: multipart/signed; protocol="application/pgp-signature";
            micalg=pgp-md5; boundary=9dgjiU4MmWPVapMU
    In-Reply-To: <19981205200346.B32334at_private>; from Ben Collins on Sat, Dec 05, 1998 at 08:03:47PM -0500
    X-Debian: PGP check passed for security officers
    Priority: urgent
    Reply-To: securityat_private
    Resent-Message-ID: <"JkYkX.A.zUB.Deya2"@murphy>
    Resent-From: debian-security-announceat_private
    X-Mailing-List: <debian-security-announceat_private> archive/latest/35
    X-Loop: debian-security-announceat_private
    Precedence: list
    Resent-Sender: debian-security-announce-requestat_private
    
    
    --9dgjiU4MmWPVapMU
    Content-Type: multipart/mixed; boundary=da4uJneut+ArUgXk
    
    
    --da4uJneut+ArUgXk
    Content-Type: text/plain; charset=us-ascii
    
    
    I just wrote this advisory. I'm currently waiting for the m68k porters
    to recompile it before releasing it.
    
    Wichert.
    
    --
    ==============================================================================
    This combination of bytes forms a message written to you by Wichert Akkerman.
    E-Mail: wakkermaat_private
    WWW: http://www.wi.leidenuniv.nl/~wichert/
    
    --da4uJneut+ArUgXk
    Content-Type: text/plain; charset=us-ascii
    Content-Disposition: attachment; filename=fte
    
    Subject: [SECURITY] New versions of fte fixes access problems
    
    We have found that the fte package as supplied in our slink (frozen
    and potato (unstable) archives does not drop its root priviliges
    after initializing the virtual console device. This allows all users
    to read and write files with root priviliges, and execute all programs
    as root.
    
    A new package (version 0.46b-4.1) has been uploaded to fix this problem.
    
    We recommend that you upgrade your fte package immediately.
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    Debian GNU/Linux 2.0 alias hamm
    -------------------------------
    
      fte was not released for this (or earlier) release.
    
    
    Debian GNU/Linux 2.1 alias slink (not released yet)
    ---------------------------------------------------
    
      Source archives:
        ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-4.1.diff.gz
          MD5 checksum: 44c60f6b5b55c80f7634eb405f3707e5
        ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-4.1.dsc
          MD5 checksum: e8991ea4fe2e298b57432e80dc5fd0b8
        ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5.orig.tar.gz
          MD5 checksum: 255f2f8cd2c210b497fdcdb0b9f964ed
    
      Intel architecture:
        ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte-console_0.46b5-4.1.deb
          MD5 checksum: 0d3d146749f68b11f6aed19d64161bbe
        ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte_0.46b5-4.1.deb
          MD5 checksum: 39a33e02915d6cc594b9170d0fc9b0f8
    
    For not yet released architectures please refer to the appropriate
    directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .
    
    --
    Debian GNU/Linux      .   Security Managers      .   securityat_private
                  debian-security-announceat_private
      Christian Hudon     .     Wichert Akkerman     .     Martin Schulze
    <chrishat_private>   .   <wakkermaat_private>  .   <joeyat_private>
    
    --da4uJneut+ArUgXk--
    
    --9dgjiU4MmWPVapMU
    Content-Type: application/pgp-signature
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    
    iQB1AwUBNmspFqjZR/ntlUftAQEF5gL9FFZaMy6PaVrnVtd+UZclrVE2t8lG9tCo
    I6UDORb989Yei76uLC8LjKiXPCgAYs/uYk5WU+g6L08iLy3RliIxgCblBj0ZIWI4
    iXzErwUiCjGGFVXXrR6CklnDxujkrtPo
    =4Whn
    -----END PGP SIGNATURE-----
    
    --9dgjiU4MmWPVapMU--
    
    
    --
    To UNSUBSCRIBE, email to debian-security-announce-requestat_private
    with a subject of "unsubscribe". Trouble? Contact listmasterat_private
    
    
    --fUYQa+Pmc3FrFX/N--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:24:40 PDT