Debian: cscope insecure temporary file |


Debian Security Advisory DSA 610-1                     [email protected]                             Martin Schulze
December 17th, 2004           

Package        : cscope
Vulnerability  : insecure temporary file
Problem-Type   : local
Debian-specific: no
CVE ID         : CAN-2004-0996
BugTraq ID     : 11697
Debian Bug     : 282815

A vulnerability has been discovered in cscope, a program to
interactively examine C source code, which may allow local users to
overwrite files via a symlink attack.

For the stable distribution (woody) this problem has been fixed in
version 15.3-1woody2.

For the unstable distribution (sid) this problem has been fixed in
version 15.5-1.

We recommend that you upgrade your cscope package.

Upgrade Instructions

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody

