Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Debian: DSA-042-1 Critical: Gnuserv Buffer Overflow Threat

debian
Calendar Grey March 9, 2001
Debian Logo
Critical vulnerability identified in Fedora's emacs and gnome-terminal packages requires immediate remediation.
Klaus Frank has found a vulnerability in the way gnuserv handled remote connections.

Summary

Klaus Frank has found a vulnerability in the way gnuserv handled
remote connections. Gnuserv is a remote control facility for Emacsen
which is available as standalone program as well as included in
XEmacs21. Gnuserv has a buffer for which insufficient boundary checks
were made. Unfortunately this buffer affected access control to
gnuserv which is using a MIT-MAGIC-COOCKIE based system. It is
possible to overflow the buffer containing the cookie and foozle
cookie comparison.

Gnuserv was derived from emacsserver which is part of GNU Emacs. It's
was reworked completely and not much is to be left over from its time
as part of GNU Emacs. Therefore the versions of emacssserver in both
Emacs19 and Emacs20 doesn't look vulnerable to this bug, they don't
even provide a MIT-MAGIC-COOKIE based mechanism.

This could lead into a remote user issue commands under
the UID of the person running gnuserv.


We recommend you upgrade your xemacs21 and gnuserv packages immediately.

wget url
will fetch the fil...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here