Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 2.1: Security Advisory on Xlockmore Local Exploit

debian
Calendar Grey August 17, 2000
Debian Logo
Important notice issued: mitigate recent risk found in xlockmore affecting Debian systems. Contact Debian security support for assistance.
There is a format string bug in all versions of xlockmore/xlockmore-gl.

Summary

Package: xlockmore, xlockmore-gl
Vulnerability type: local exploit
Debian-specific: no

There is a format string bug in all versions of xlockmore/xlockmore-gl.
Debian 2.1 (slink) installs xlock setgid by default, and this exploit
can be used to gain read access to the shadow file. We recommend
upgrading immediately.

xlockmore is normally installed as an unprivileged program in Debian 2.2
(potato) and is not vulnerable in that configuration. xlockmore may be
setuid/setgid for historical reasons or after upgrading from a previous
Debian release; consult README.Debian in /usr/doc/xlockmore or
/usr/doc/xlockmore-gl for information about xlock privileges and how to
disable them. If your local environment requires xlock to be setgid, or
if in doubt, you should upgrade to a fixed package immediately.

Fixed packages are available in xlockmore/xlockmore-gl 4.12-5 for Debian
2.1 (slink) and xlockmore/xlockmore-gl 4.15-9 for Debian 2.2 (potato).

wget url
will fetch the file for you
dpkg -i file.deb
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here