Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Debian 3.0: 316-2 Critical: Slashem Buffer Overflow Threat

debian
Calendar Grey June 12, 2003
Scroller Debian
-------------------------------------------------------------------------- Debian Security Advisory
The slashem package is vulnerable to a buffer overflow exploited via a long '-s' command line option

Summary

The slashem package is vulnerable to a buffer overflow exploited via a
long '-s' command line option. This vulnerability could be used by an
attacker to gain gid 'games' on a system where slashem is installed.

Note that slashem does not contain the file permission problem
CAN-2003-0359, addressed in nethack in DSA-316-1.

For the stable distribution (woody) these problems have been fixed in
version 0.0.6E4F8-4.0woody3.

For the old stable distribution (potato) problem xxx has been fixed in
version 0.0.5E7-3potato1.

For the unstable distribution (sid) these problems are fixed in
version 0.0.6E4F8-6.

We recommend that you update your slashem package.

Upgrade Instructions
--------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: slashem

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.