Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian GNU/Linux 3.1: DSA 843-1 Moderate: arc Insecure File Attack

debian
Calendar Grey October 5, 2005
Debian Logo
Remedies for vulnerable file permissions in arc packages for Debian Sarge, boosting overall system safety.
Updated package.

Summary


Eric Romang discovered that the ARC archive program under Unix
creates a temporary file with insecure permissions which may lead
to an attacker stealing sensitive information.

CAN-2005-2992

Joey Schulze discovered that the temporary file was created in an
insecure fashion as well, leaving it open to a classic symlink
attack.

The old stable distribution (woody) does not contain arc packages.

For the stable distribution (sarge) these problems have been fixed in
version 5.21l-1sarge1.

For the unstable distribution (sid) these problems have been fixed in
version 5.21m-1.

We recommend that you upgrade your arc package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install correct...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here