[SECURITY] New versions of smtp-refuser fixes security hole

From: Aleph One (aleph1at_private)
Date: Fri Aug 20 1999 - 12:37:03 PDT

  • Next message: Aleph One: "[SECURITY] Current versions of seyon may contain malicious code"

    --mXDO3udm/xYWQeMQ
    Content-Type: text/plain; charset=us-ascii
    
    This bug was experienced in May 1999 but wasn't reported on this
    channel yet.
    
    Former versions of the smtp-refuser package came with unchecked
    logging facility to /tmp/log.  This allowed deleting arbitrary,
    root-owned files by any user who has write access to /tmp.
    
    We recommend you upgrade your smtp-refuser package.
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    
    Debian GNU/Linux 2.1 alias slink
    --------------------------------
    
      Source archives:
    
        ftp://ftp.debian.org/debian/dists/proposed-updates/smtp-refuser_1.0.1.dsc
          MD5 checksum: 282eb6e299e48bf47c773c88dc45f140
        ftp://ftp.debian.org/debian/dists/proposed-updates/smtp-refuser_1.0.1.tar.gz
          MD5 checksum: 5059fcc13077f7e959f417af8d403dda
    
      Alpha architecture:
    
        ftp://ftp.debian.org/debian/dists/proposed-updates/smtp-refuser_1.0.1_alpha.deb
          MD5 checksum: 2d7c4c8ba5226942af1d505eb06dca02
    
      Intel ia32 architecture:
    
        ftp://ftp.debian.org/debian/dists/proposed-updates/smtp-refuser_1.0.1_i386.deb
          MD5 checksum: 45a32aece01c4c3a5a329d6c857da94b
    
      Motorola 680x0 architecture:
    
        ftp://ftp.debian.org/debian/dists/proposed-updates/smtp-refuser_1.0.1_m68k.deb
          MD5 checksum: f8f733dc4dd8971b891fc4bfa00412b8
    
      Sun Sparc architecture:
    
        ftp://ftp.debian.org/debian/dists/proposed-updates/smtp-refuser_1.0.1_sparc.deb
          MD5 checksum: c60a3b0bdf77baace00c9d670a174a01
    
    
    Debian GNU/Linux unstable alias potato
    --------------------------------------
    
      Source archives:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/source/mail/smtp-refuser_1.0.1.dsc
          MD5 checksum: 282eb6e299e48bf47c773c88dc45f140
        ftp://ftp.debian.org/debian/dists/unstable/main/source/mail/smtp-refuser_1.0.1.tar.gz
          MD5 checksum: 5059fcc13077f7e959f417af8d403dda
    
      Alpha architecture:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/binary-alpha/mail/smtp-refuser_1.0.1.deb
          MD5 checksum: d8ee4cba999534c1a488a7a11f2791da
    
      ARM architecture:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/binary-arm/mail/smtp-refuser_1.0.1.deb
          MD5 checksum: 92ffab6117f2075614aeaaf2e180ff59
    
      Intel ia32 architecture:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/binary-i386/mail/smtp-refuser_1.0.1.deb
          MD5 checksum: 45a32aece01c4c3a5a329d6c857da94b
    
      Motorola 680x0 architecture:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/binary-m68k/mail/smtp-refuser_1.0.1.deb
          MD5 checksum: 43cf12edcdc1a7eeb6e317e218da8ba5
    
      PowerPC architecture:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/binary-powerpc/mail/smtp-refuser_1.0.1.deb
          MD5 checksum: 42a651ed5647c0495b9f77386df6e124
    
      Sun Sparc architecture:
    
        ftp://ftp.debian.org/debian/dists/unstable/main/binary-sparc/mail/smtp-refuser_1.0.1.deb
          MD5 checksum: ecda66ea8d37ae48acbc0f4fbcc0de14
    
    
    --
    Debian GNU/Linux      .    Security Managers     .   securityat_private
                  debian-security-announceat_private
      Christian Hudon     .     Wichert Akkerman     .     Martin Schulze
    <chrishat_private>   .   <wakkermaat_private>  .   <joeyat_private>
    
    --mXDO3udm/xYWQeMQ
    Content-Type: application/pgp-signature
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    
    iQCVAwUBN7u+4RRNm5Suj3z1AQEbDwP+J7OxplH3Y4irfoT2yZ3ixIlI8sw0i755
    ajS41cEi792qb75AXvIKq7V3z9Yd8UXG0F5PLooejKP69W43ooX6rd9ikBQT2g4V
    gHzYbsW9kD+MM8ERLLgPOjvOyNXX6VKcxtAfhxS++zmN0/J2SC3ZFwPZKG1c0YGh
    133DOzj5QAo=
    =27Nh
    -----END PGP SIGNATURE-----
    
    --mXDO3udm/xYWQeMQ--
    
    
    --
    To UNSUBSCRIBE, email to debian-security-announce-requestat_private
    with a subject of "unsubscribe". Trouble? Contact listmasterat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:57:43 PDT