Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian DSA 279-1 Critical: Metrics Package Insecure File Creation

debian
Calendar Grey April 7, 2003
Debian Logo
Critical advisory for Debian on metrics package vulnerability exposing users to local file overwrite attacks. Upgrade recommended.
Two scripts in the metrics package, "halstead" and "gather_stats", open temporary files without taking appropriate security precautions.

Summary

Paul Szabo and Matt Zimmerman discoverd two similar problems in
metrics, a tools for software metrics. Two scripts in this package,
"halstead" and "gather_stats", open temporary files without taking
appropriate security precautions. "halstead" is installed as a user
program, while "gather_stats" is only used in an auxiliary script
included in the source code. These vulnerabilities could allow a
local attacker to overwrite files owned by the user running the
scripts, including root.

The stable distribution (woody) is not affected since it doesn't
contain a metrics package anymore.

For the old stable distribution (potato) this problem has been fixed
in version 1.0-1.1.

The unstable distribution (sid) is not affected since it doesn't
contain a metrics package anymore.

We recommend that you upgrade your metrics package.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package ma...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: metrics

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here