Debian: New geneweb packages fix insecure file operations

    Date19 Apr 2005
    CategoryDebian
    5225
    Posted ByJoe Shakespeare
    Updated package.
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 712-1                     This email address is being protected from spambots. You need JavaScript enabled to view it.
    http://www.debian.org/security/                             Martin Schulze
    April 19th, 2005                        http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : geneweb
    Vulnerability  : insecure file operations
    Problem-Type   : local
    Debian-specific: yes
    CVE ID         : CAN-2005-0391
    Debian Bug     : 304405
    
    Tim Dijkstra discovered a problem during the upgrade of geneweb, a
    genealogy software with web interface.  The maintainer scripts
    automatically converted files without checking their permissions and
    content, which could lead to the modification of arbitrary files.
    
    For the stable distribution (woody) this problem has been fixed in
    version 4.06-2woody1.
    
    For the unstable distribution (sid) this problem has been fixed in
    version 4.10-7.
    
    We recommend that you upgrade your geneweb package.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 3.0 alias woody
    - --------------------------------
    
      Source archives:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1.dsc
          Size/MD5 checksum:      622 42f4904be438272ef8cdc58c209bf69e
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1.diff.gz
          Size/MD5 checksum:    23312 8a6772692840aaa3a8190f3c620a93c7
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06.orig.tar.gz
          Size/MD5 checksum:   832896 a64a4373cb82d6a3044718c7345e45f7
    
      Alpha architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_alpha.deb
          Size/MD5 checksum:  2337090 858feee271e9273832c88d48ba328a12
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_alpha.deb
          Size/MD5 checksum:   208060 f7307a991ec6bc392921d90abdc81ca2
    
      ARM architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_arm.deb
          Size/MD5 checksum:  1944856 82b8aebab5bb58d37d15b999a4335f2a
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_arm.deb
          Size/MD5 checksum:   169726 7839aa9156ee97f9d1f3c4f86dd550c3
    
      Intel IA-32 architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_i386.deb
          Size/MD5 checksum:  1684856 2a1bc1f0ec1fc6c3f7ef7c52fd1e94d8
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_i386.deb
          Size/MD5 checksum:   144654 6894d141467665242c11498ad8d19c7e
    
      Intel IA-64 architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_ia64.deb
          Size/MD5 checksum:   985874 1ab07405b51d714f67947bbdb2b75556
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_ia64.deb
          Size/MD5 checksum:   108438 4885192511533339a3f4bbac1f46e3af
    
      HP Precision architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_hppa.deb
          Size/MD5 checksum:   865514 2e9ac4cb55344f560c09305d8e5ff69a
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_hppa.deb
          Size/MD5 checksum:    88544 f9bb191412501d5bb0af4f1e3ad3da8d
    
      Motorola 680x0 architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_m68k.deb
          Size/MD5 checksum:   769174 160c16c3ec87483ea98bf2d27d21791d
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_m68k.deb
          Size/MD5 checksum:    72536 91fb0ee658037ed95eacf536d4a85066
    
      Big endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_mips.deb
          Size/MD5 checksum:   830996 744a10d4b0b6274130243f20b5fd61b8
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_mips.deb
          Size/MD5 checksum:    82986 e0ad1d6ec21c6e3d3c05f3d415dc7464
    
      Little endian MIPS architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_mipsel.deb
          Size/MD5 checksum:   828712 f662f4bfd37628765ff6ed5f84db1ced
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_mipsel.deb
          Size/MD5 checksum:    82488 f59385de1518114ca79d4fafdd671c70
    
      PowerPC architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_powerpc.deb
          Size/MD5 checksum:  1974276 6f7b75c7a7110573a60e23ee148ad08e
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_powerpc.deb
          Size/MD5 checksum:   172650 722401a02a51b2e0e56cb3192fd0112c
    
      IBM S/390 architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_s390.deb
          Size/MD5 checksum:   806318 9050118b04fd2ac2191a42626a0f475e
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_s390.deb
          Size/MD5 checksum:    78592 ef1d41ec105bff3fb06d7666ba1a5088
    
      Sun Sparc architecture:
    
        http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2woody1_sparc.deb
          Size/MD5 checksum:  2014300 a419b10c08cf4612a5acba067f4adc3f
        http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2woody1_sparc.deb
          Size/MD5 checksum:   176650 8e4c69e79adc7df3de7464981c8e8d31
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"67","type":"x","order":"1","pct":57.26,"resources":[]},{"id":"88","title":"Should be more technical","votes":"16","type":"x","order":"2","pct":13.68,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"34","type":"x","order":"3","pct":29.06,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.