Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian 3.0: DSA 292-1 Major: Mime-Support Insecure File Creation Issue

debian
Calendar Grey April 22, 2003
Debian Logo
Debian Security Advisory DSA 292-1 tackles a file mismanagement issue in mime-support, urging package updates for safety.
When a temporary file is to be used it is created insecurely, allowing an attacker to overwrite arbitrary under the user id of the person executing run-mailcap, most probably root.

Summary

Colin Phipps discovered several problems in mime-support, that contains
support programs for the MIME control files 'mime.types' and 'mailcap'.
When a temporary file is to be used it is created insecurely, allowing
an attacker to overwrite arbitrary under the user id of the person
executing run-mailcap, most probably root. Additionally the program did
not properly escape shell escape characters when executing a command.
This is unlikely to be exploitable, though.

For the stable distribution (woody) these problems have been fixed in
version 3.18-1.1.

For the old stable distribution (potato) these problems have been
fixed in version 3.9-1.1.

For the unstable distribution (sid) these problems have been
fixed in version 3.22-1.

We recommend that you upgrade your mime-support packages.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list a...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: mime-support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here