[SECURITY] ftpwatch package has major security problems

From: Jamie Fifield (fifieldat_private)
Date: Sun Jan 17 1999 - 07:48:22 PST

  • Next message: Darren Reed: "Re: Outlook 98 Security "Feature""

    -----BEGIN PGP SIGNED MESSAGE-----
    
    We have found that the ftpwatch package as distributed in Debian
    GNU/Linux 1.3 and later distributions has a security problem which makes
    it trivial for users to gain root access.
    
    We recommend that you remove the ftpwatch package immediately.
    
    We will be working on a new version of ftpwatch to address these issues and
    will announce that in a new advisory.
    
    - --
    Debian GNU/Linux      .   Security Managers      .   securityat_private
                  debian-security-announceat_private
      Christian Hudon     .     Wichert Akkerman     .     Martin Schulze
    <chrishat_private>   .   <wakkermaat_private>  .   <joeyat_private>
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    Charset: noconv
    
    iQB1AwUBNqHg66jZR/ntlUftAQGzgQL8DNAvGsGP3T3oMOuEBlJ2Tu3XkoE8x88e
    olp7AML4hjCna/y14uoa+nUsekcZR4uaDoz3pPI+gir4YwA0FP9siwNafTC1Hjj6
    nh+5/l0tIjko01xEzr4d9glLG4ygKOJD
    =bm2E
    -----END PGP SIGNATURE-----
    
    
    --
    To UNSUBSCRIBE, email to debian-security-announce-requestat_private
    with a subject of "unsubscribe". Trouble? Contact listmasterat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:29:06 PDT