Debian: xsok Missing privilege release

    Date30 Dec 2003
    CategoryDebian
    2531
    Posted ByLinuxSecurity Advisories
    Steve Kemp discovered a problem in xsok, a single player strategy gamefor X11, related to the Sokoban game, which leads a user to executearbitrary commands under the GID of games.
    
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Debian Security Advisory DSA 405-1                     This email address is being protected from spambots. You need JavaScript enabled to view it. 
    http://www.debian.org/security/                             Martin Schulze
    December 30th, 2003                      http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : xsok
    Vulnerability  : missing privelige release
    Problem-Type   : local
    Debian-specific: no
    CVE ID         : CAN-2003-0949
    
    Steve Kemp discovered a problem in xsok, a single player strategy game
    for X11, related to the Sokoban game, which leads a user to execute
    arbitrary commands under the GID of games.
    
    For the stable distribution (woody) this problem has been fixed in
    version 1.02-9woody2.
    
    For the unstable distribution (sid) this problem has been fixed in
    version 1.02-11.
    
    We recommend that you upgrade your xsok package.
    
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian GNU/Linux 3.0 alias woody
    - --------------------------------
    
      Source archives:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2.dsc
          Size/MD5 checksum:      575 5e3f7f8513b7fb3e8fa1ebfa56a2b4bc
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2.diff.gz
          Size/MD5 checksum:     5616 6c17b1f0201f583c770b42334be33cb4
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02.orig.tar.gz
          Size/MD5 checksum:   114085 f961b329e6577ebefcaa0acece9c94c8
    
      Alpha architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_alpha.deb
          Size/MD5 checksum:    69860 45a8699a82fb7da43a4ca28f9579fb62
    
      ARM architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_arm.deb
          Size/MD5 checksum:    64018 0f2ac33af74901cd52d31cb23e2b5b4f
    
      Intel IA-32 architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_i386.deb
          Size/MD5 checksum:    61822 35ede5adbfbdad30eb7ecdc1137f5f33
    
      Intel IA-64 architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ia64.deb
          Size/MD5 checksum:    79138 5ff4f9683dce6582219d4907c3f3bc5c
    
      HP Precision architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_hppa.deb
          Size/MD5 checksum:    68178 fa756bb317a7162ac9df2a0b0576ee9a
    
      Motorola 680x0 architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_m68k.deb
          Size/MD5 checksum:    61204 6b32053cc307b3c9bfe4b3036fcab30f
    
      Big endian MIPS architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_mips.deb
          Size/MD5 checksum:    68402 b23adc954aaf6a23ac3e118d9c4150b6
    
      Little endian MIPS architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_mipsel.deb
          Size/MD5 checksum:    68338 061b40e0768f906db728cf9d3b8574e6
    
      PowerPC architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_powerpc.deb
          Size/MD5 checksum:    64626 6f95af173c40cc7e2d00501d80c0e308
    
      IBM S/390 architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_s390.deb
          Size/MD5 checksum:    64706 42386e9b13539154f214a20c464b9988
    
      Sun Sparc architecture:
    
         http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_sparc.deb
          Size/MD5 checksum:    66278 4d061f87360819298c481eb17dd43881
    
    
      These files will probably be moved into the stable distribution on
      its next revision.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb  http://security.debian.org/ stable/updates main
    For dpkg-ftp:  ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    Package info: `apt-cache show ' and  http://packages.debian.org/
    
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)
    
    iD8DBQE/8UlwW5ql+IAeqTIRAivnAJ47ZNx8ciwmJef3TfpZpZDfbAR6XQCdFT5G
    AAiln4U8+sjX4HqeAMhjH8s=
    =PFVG
    -----END PGP SIGNATURE-----
    
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"23","type":"x","order":"1","pct":56.1,"resources":[]},{"id":"88","title":"Should be more technical","votes":"5","type":"x","order":"2","pct":12.2,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"13","type":"x","order":"3","pct":31.71,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.